Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
- From: Jason Hellenthal <jhell@xxxxxxxxxx>
- Date: Sun, 8 May 2011 03:52:03 -0400
Edho,
On Sun, May 08, 2011 at 09:15:28AM +0700, Edho P Arief wrote:
On Sun, May 8, 2011 at 5:31 AM, Jamie Landeg Jones <jamie@xxxxxxxxxxxxxx> wrote:
All the same, I've sent a PR [1] with some doc patches to make people
more aware of this -- fulfilling my promise of 2+ years ago :S
Thanks!
Chris
[1] http://www.freebsd.org/cgi/query-pr.cgi?pr=156853
Um. Some problems here.
A jail won't work for not-root users if the jail root directory is chmod 700 - although
there is obviously a 'chroot' running withing the jail, the jailed user still needs
to have read permission from the hosts / -- chmod 700 therefore locks all non-root
users out.
It's weird - I don't remember having such problem after setting jails'
root directory permission to 700. I don't have the system anymore so I
can't verify it just yet.
It should also be noted here that the jailed root user also has permission
to chmod(1) '/' to anything he or she wants unless you have taken
precaution to not allow that. I would reccoment storing your jails two
levels deep into a directory and chmod(1) 700 the first level to prevent
access from the host and from the jailed root user changing the perms.
--
Regards, (jhell)
Jason Hellenthal
Attachment:
pgppwT3f5M2h2.pgp
Description: PGP signature
- Follow-Ups:
- Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
- From: Chris Rees
- Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
- From: Edho P Arief
- Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
- References:
- Rooting FreeBSD , Privilege Escalation using Jails (Pétur)
- From: Daniel Jacobsson
- Re: Rooting FreeBSD , Privilege Escalation using Jails (Pétur)
- From: Daniel Jacobsson
- Re: Rooting FreeBSD , Privilege Escalation using Jails (Pétur)
- From: Mark Felder
- Re: Rooting FreeBSD , Privilege Escalation using Jails (Pétur)
- From: Chris Rees
- Re: Rooting FreeBSD , Privilege Escalation using Jails (P�tur)
- From: Jamie Landeg Jones
- Re: Rooting FreeBSD , Privilege Escalation using Jails (P�tur)
- From: Edho P Arief
- Rooting FreeBSD , Privilege Escalation using Jails (Pétur)
- Prev by Date: Re: Rooting FreeBSD , Privilege Escalation using Jails (P�tur)
- Next by Date: Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
- Previous by thread: Re: Rooting FreeBSD , Privilege Escalation using Jails (P�tur)
- Next by thread: Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
- Index(es):
Relevant Pages
|