Re: Sandboxing
- From: "mal content" <artifact.one@xxxxxxxxxxxxxx>
- Date: Thu, 9 Nov 2006 10:22:59 +0000
On 09/11/06, Luke Crawford <lsc@xxxxxxxxx> wrote:
jail is the best sandbox FreeBSD has; if that's to heavy, simply run it
setuid to another user that doesn't have permission to anything- it's not
as good of a sandbox, but it's lightweight.
Of course there is another problem with this approach: a different UID isn't
allowed to connect to :0.0 on the X server under the FreeBSD default
security settings for X.
MC
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- References:
- Sandboxing
- From: mal content
- Re: Sandboxing
- From: mal content
- Re: Sandboxing
- From: Lowell Gilbert
- Re: Sandboxing
- From: Erik Trulsson
- Re: Sandboxing
- From: mal content
- Re: Sandboxing
- From: Luke Crawford
- Re: Sandboxing
- From: mal content
- Re: Sandboxing
- From: Luke Crawford
- Sandboxing
- Prev by Date: Re: Sandboxing
- Next by Date: Re: Sandboxing
- Previous by thread: Re: Sandboxing
- Next by thread: Re: Sandboxing
- Index(es):
Relevant Pages
|
|