Re: Configuration differences for jails

From: Joerg Sonnenberger (joerg_at_britannica.bec.de)
Date: 04/21/05

  • Next message: Devon_at_Jovi.Net: "Re: sshd dieing? after applying FreeBSD-SA-03:12.openssh"
    Date: Thu, 21 Apr 2005 13:43:59 +0200
    To: freebsd-hackers@freebsd.org
    
    

    On Thu, Apr 21, 2005 at 07:39:08AM -0400, c0ldbyte wrote:
    > Now if that last question is correct and thats the proccess you are using
    > to create a jail then depending on the situation wouldnt that inturn
    > defeat some of the main purposes of the jail, like the following. If you
    > mounted your "/bin" on "/mnt/jail/bin" then if a person that was looking
    > to break in and effect the system that is currently locked in the "jail"
    > all he would have to do is just write something to the "jail/bin" which is
    > actualy your root "/bin" and then the next time a binary is used from your
    > root directories it could still infect the rest of the system ultimately
    > defeating the purpose of what you just set up. To my understanding and use
    > a jail is somewhat totaly independent of the OS that it resides in and
    > wont be if you are using nullfs to mount root binary directories on it.

    ro mount as written by grant parent protects against this.

    Joerg
    _______________________________________________
    freebsd-hackers@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
    To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org"


  • Next message: Devon_at_Jovi.Net: "Re: sshd dieing? after applying FreeBSD-SA-03:12.openssh"

    Relevant Pages

    • Jail function 6.x
      ... I`ve been using jails in FreeBSD for some time now and its a good solution for my purposes. ... I know there was some patch for 4.x which did this, so I was wondering if some one got around to patch the jail function for 5.x. ...
      (freebsd-questions)
    • Re: Configuration differences for jails
      ... >> defeat some of the main purposes of the jail, ... >> wont be if you are using nullfs to mount root binary directories on it. ... readonly mounts may be a good choice. ... BUT if we do some things related to the /etc files, such as passwd, ro ...
      (freebsd-hackers)
    • Re: Delay for President!
      ... >defeat the democrats. ... Maybe he can run from jail like Larouche. ...
      (alt.politics.bush)