Re: jail & security

From: Alexey Zakirov (frank@agava.com)
Date: 08/23/01


Date: Thu, 23 Aug 2001 22:39:47 +0400 (MSD)
From: Alexey Zakirov <frank@agava.com>
To: Shannon Johnson <shannon@needhams.com>


> Alexey, correct me if I am wrong, but Igor was asking if it was possible to

> limit "resources allocated by each VM (jail)." I simply addressed it on
> this issue and not on "root compromise." That is why I refered him to login
> classes.
>
> By the way, it is nice to know that you would trash my system if given root
> access within the jail. However, there are ways to prevent people like
> yourself from destroying a system (e.g. read only file system, setting the
> system immutable flag, etc.)

jail(2) is GREAT feature. I'm thank PHK for did it. It's really pretend to
be a great security help in the unixos.

> Remind me to never give you a shell account.

It IS a problem. Shell is not a problem, but there is the PR/18209.
If you want a shell account: http://register.h1.ru/index.shtml

*** WBR, Alexey Zakirov (frank@agava.com)

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: jail & security
    ... On Thu, 23 Aug 2001, Alexey Zakirov wrote: ... |> Alexey, correct me if I am wrong, but Igor was asking if it was possible to ... |> this issue and not on "root compromise." ... |> Remind me to never give you a shell account. ...
    (FreeBSD-Security)
  • hidden login files
    ... In a moment of extreme stupidity I have deleted all hidden file from my ... shell account (ex: .profile. ... .login, etc). ...
    (comp.unix.questions)
  • login hidden files
    ... In a moment of extreme stupidity I have deleted all hidden files from my ... shell account (ex: .profile. ... .login, etc). ...
    (comp.unix.shell)
  • Re: Reject login if invalid home directory
    ... > How, if you can, do you reject a login request if the home directory ... whatever the shell account uses), but you'll notice that root's default ... DeeDee, don't press that button! ...
    (comp.unix.solaris)