Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 20 Jan 2002 21:40:48 +0100
From:      Slawek Zak <zaks@prioris.mini.pw.edu.pl>
To:        freebsd-security@FreeBSD.ORG
Subject:   Re: identd inside of jail
Message-ID:  <87wuycycvj.fsf@pf39.warszawa.sdi.tpnet.pl>
In-Reply-To: <Pine.NEB.3.96L.1011207115009.42818D-100000@fledge.watson.org> (Robert Watson's message of "Fri, 7 Dec 2001 11:52:57 -0500 (EST)")
References:  <Pine.NEB.3.96L.1011207115009.42818D-100000@fledge.watson.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 7 Dec 2001, Robert Watson told this:
> This problem is fixed in 5.0-CURRENT as it performs two checks in udp and
> tcp getcred: first, it checks for privilege (and permits the jail to
> succeed), and second, it checks whether the connection in question is
> visible to the current jail.

And what about check if connection was initiated from server, just like it's
done in OpenBSD? ;)

/S
-- 
hundred-and-one symptoms of being an internet addict:
196. Your computer costs more than your car.
* Suavek Zak / PGP: finger://zaks@prioris.mini.pw.edu.pl

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?87wuycycvj.fsf>