Re: I just broke out of a FreeBSD jail.. Known bug??



On Dec 28, 2007, at 13:41 , Edwin Groothuis wrote:

On Fri, Dec 28, 2007 at 01:15:38PM +0100, Johan Str?m wrote:
Thats my home dir on core!.. That should very much not be visible
there! I have full access now (from the wrong jail!)

Known bug or did I just stumble upon something pretty bad??

You didn't really break out of it, the person who managed the machine
did something he shouldn't have done: Moving the directories while
the jail(s) were running. It should be mentioned in the BUGS section
of the jail(8) command.


Yes, thats true.. Without "super-root" doing that the "breakout" would never happen. But still a bug, so yes I guess it should be mentioned in BUGS (and handbook too? not sure where this kind of "special features" are noted) unless its fixed.

--
Johan

_______________________________________________
freebsd-stable@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "freebsd-stable-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: I just broke out of a FreeBSD jail.. Known bug??
    ... But still a bug, so yes I guess it should be mentioned in BUGS (and handbook too? ... As long as untrusted processes are working with the file system namespace exposed to the jail, the privileged root user should be very cautious about trusting those bits of namespace, just as they should be cautious with bits of file system namespace writable by regular users. ...
    (freebsd-stable)
  • Re: What President Bush needs to do with the appropriations bill
    ... or some form of higher intelligence. ... OJ returned as a bug and had to work his way back up the moral evolutionary ... As for jail, believing he should go to jail for Brown/Goldman is a waste of ... More Cartoons with a Touch of Magic? ...
    (misc.news.internet.discuss)
  • American Jails - the real facts
    ... did a lot of filiming in a tough jail. ... Last night the show gave coverage of a prisoner who was being claiming ... He found a bug in the yard and kept it. ... The jail's lawyer talked about the case and said 30 USD was just too ...
    (alt.politics)
  • jails and sysctl in freebsd 6.0
    ... Bug or something, look at this ... You can't change the hostname ... in jail. ... But booting OS hangs a little ...
    (FreeBSD-Security)
  • Re: Possible security issue with jails
    ... >>I'm not sure if this is actually an issue, feature or a bug, but I have found ... > Only if you leave bpf devices in the devfs mounted on the jail. ... To unsubscribe, ...
    (FreeBSD-Security)