Re: Possible security issue with jails

From: Micah (micah_at_micah.ws)
Date: 01/12/05

  • Next message: Christian Brueffer: "Biometric Authentication for BSD/Linux (Forward)"
    Date: Wed, 12 Jan 2005 00:35:08 +0000
    To: freebsd-security@freebsd.org
    
    

    This was the info I needed. Thanks!

    -micah

    On Tue, Jan 11, 2005 at 11:05:43PM +0100, Poul-Henning Kamp wrote:
    > In message <20050111221055.GD68350@micah.tamu.edu>, Micah writes:
    > >Howdy!
    > >
    > >I'm not sure if this is actually an issue, feature or a bug, but I have found
    > >that inside a jail, the jailed root user is able to sniff traffic (and enable
    > >promiscuous mode) on at least the interface of the IP address the jail is attached
    > >to.
    >
    > Only if you leave bpf devices in the devfs mounted on the jail.
    >
    > --
    > Poul-Henning Kamp | UNIX since Zilog Zeus 3.20
    > phk@FreeBSD.ORG | TCP/IP since RFC 956
    > FreeBSD committer | BSD since 4.3-tahoe
    > Never attribute to malice what can adequately be explained by incompetence.
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Christian Brueffer: "Biometric Authentication for BSD/Linux (Forward)"

    Relevant Pages

    • Re: Fluxbox and Debian menu
      ... Wayne Topa wrote: ... It is a feature, not a bug. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: UNSUSCRIBE
      ... display the list info at the end. ... More a feature than a bug. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: ATTN: Barbara Oncay
      ... Paul Johnson wrote: ... That's not a bug, but a feature one should be aware of. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: Possible security issue with jails
      ... In message <20050111221055.GD68350@micah.tamu.edu>, Micah writes: ... >I'm not sure if this is actually an issue, feature or a bug, but I have found ... >promiscuous mode) on at least the interface of the IP address the jail is attached ...
      (FreeBSD-Security)
    • see processes owned by other users
      ... With one exception, if a process was started in jail with the same UID (but ... Is there a feature or bug? ... To unsubscribe, ...
      (freebsd-questions)