Re: Sysmask security challenge: 1 week and +300 arbitrary code assaults, still resisting

From: azuredu (xiao_at_unice.fr)
Date: 04/20/05


Date: 20 Apr 2005 06:11:06 -0700


> I run my Web browser as an unprivileged user in a chroot ghetto
> that has no setuid programs, no devices and no files shared with

Please read the following for discussion of what can be secured for a
browser and what cannot.

http://wims.unice.fr/sysmask/doc/example.txt

In any case, sysmask offers more protection than a simple chroot,
because the process can be made much less exposed to kernel
vulnerabilities.


Quantcast