From owner-freebsd-current@FreeBSD.ORG Mon Feb 6 20:29:27 2006 Return-Path: X-Original-To: current@freebsd.org Delivered-To: freebsd-current@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A073816A422; Mon, 6 Feb 2006 20:29:27 +0000 (GMT) (envelope-from bkoenig@cs.tu-berlin.de) Received: from efacilitas.de (smtp.efacilitas.de [85.10.196.108]) by mx1.FreeBSD.org (Postfix) with ESMTP id D4A9C43D49; Mon, 6 Feb 2006 20:29:26 +0000 (GMT) (envelope-from bkoenig@cs.tu-berlin.de) Received: from eurystheus.local (port-212-202-169-72.dynamic.qsc.de [212.202.169.72]) by efacilitas.de (Postfix) with ESMTP id 8D5AC4C579; Mon, 6 Feb 2006 21:38:46 +0100 (CET) Received: from [192.168.1.2] (muhkuh.local [192.168.1.2]) by eurystheus.local (Postfix) with ESMTP id 9DCD35285D; Mon, 6 Feb 2006 21:28:04 +0100 (CET) Message-ID: <43E7B1A7.8010501@cs.tu-berlin.de> Date: Mon, 06 Feb 2006 21:29:27 +0100 From: =?ISO-8859-15?Q?Bj=F6rn_K=F6nig?= User-Agent: Mozilla Thunderbird 1.0.7 (Windows/20050923) X-Accept-Language: de-DE, de, en-us, en MIME-Version: 1.0 To: Andre Oppermann References: <43E60708.9000902@cs.tu-berlin.de> <43E7494B.9040401@freebsd.org> In-Reply-To: <43E7494B.9040401@freebsd.org> Content-Type: text/plain; charset=ISO-8859-15; format=flowed Content-Transfer-Encoding: 8bit Cc: current@freebsd.org Subject: Re: unprivileged users are able to kill certain jailed processes X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 06 Feb 2006 20:29:27 -0000 Andre Oppermann schrieb: > [...] If you have normal users on the host and > have jails under the same user id then, yea, tough luck. You're not > supposed to do that. [...] Yes, I can prevent from overlapping UIDs, but how to prevent from that if host administrator and jail administrator are two independent parties? It requires much more carefulness and precautions. Regards Björn