Re: Possible security issue with jails

From: Poul-Henning Kamp (phk_at_phk.freebsd.dk)
Date: 01/11/05

  • Next message: Micah: "Re: Possible security issue with jails"
    To: Micah <micah@micah.ws>
    Date: Tue, 11 Jan 2005 23:05:43 +0100
    
    

    In message <20050111221055.GD68350@micah.tamu.edu>, Micah writes:
    >Howdy!
    >
    >I'm not sure if this is actually an issue, feature or a bug, but I have found
    >that inside a jail, the jailed root user is able to sniff traffic (and enable
    >promiscuous mode) on at least the interface of the IP address the jail is attached
    >to.

    Only if you leave bpf devices in the devfs mounted on the jail.

    -- 
    Poul-Henning Kamp       | UNIX since Zilog Zeus 3.20
    phk@FreeBSD.ORG         | TCP/IP since RFC 956
    FreeBSD committer       | BSD since 4.3-tahoe    
    Never attribute to malice what can adequately be explained by incompetence.
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Micah: "Re: Possible security issue with jails"

    Relevant Pages

    • Re: I just broke out of a FreeBSD jail.. Known bug??
      ... But still a bug, so yes I guess it should be mentioned in BUGS (and handbook too? ... As long as untrusted processes are working with the file system namespace exposed to the jail, the privileged root user should be very cautious about trusting those bits of namespace, just as they should be cautious with bits of file system namespace writable by regular users. ...
      (freebsd-stable)
    • Re: What President Bush needs to do with the appropriations bill
      ... or some form of higher intelligence. ... OJ returned as a bug and had to work his way back up the moral evolutionary ... As for jail, believing he should go to jail for Brown/Goldman is a waste of ... More Cartoons with a Touch of Magic? ...
      (misc.news.internet.discuss)
    • American Jails - the real facts
      ... did a lot of filiming in a tough jail. ... Last night the show gave coverage of a prisoner who was being claiming ... He found a bug in the yard and kept it. ... The jail's lawyer talked about the case and said 30 USD was just too ...
      (alt.politics)
    • jails and sysctl in freebsd 6.0
      ... Bug or something, look at this ... You can't change the hostname ... in jail. ... But booting OS hangs a little ...
      (FreeBSD-Security)
    • Re: Possible security issue with jails
      ... >>I'm not sure if this is actually an issue, feature or a bug, but I have found ... > Only if you leave bpf devices in the devfs mounted on the jail. ... To unsubscribe, ...
      (FreeBSD-Security)