OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Michael Richardson (mcrsandelman.ottawa.on.ca)
Date: Tue Jul 17 2001 - 14:28:14 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    >>>>> "gabriel" == gabriel rosenkoetter <greclipsed.net> writes:
        gabriel> While we're at it, shall chroot() disallow compromised services
        gabriel> running within a jail from attacking other hosts? Seems within the
        gabriel> same scope to me. (That is, I just don't think it's doable.)

      chroot(2) should not.
      (I do not even think that the fchdir() checks should be done. I've used
    used the fact that you can fchdir() out of the chroot in some applications)
      
      But, I think that we should offer a facility like jail(2), etc. that does
    what is being asked for.

    ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [
    ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[
    ] mcrsandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[
    ] panic("Just another NetBSD/notebook using, kernel hacking, security guy"); [