Date: Mon, 09 May 2011 12:53:44 +0200 From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= <des@des.no> To: Jason Hellenthal <jhell@DataIX.net> Cc: Jamie Landeg Jones <jamie@bishopston.net>, freebsd-security@freebsd.org, feld@feld.me, Edho P Arief <edhoprima@gmail.com>, Chris Rees <utisoft@gmail.com> Subject: Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur) Message-ID: <86fwoof8lj.fsf@ds4.des.no> In-Reply-To: <20110508173931.GA2757@DataIX.net> (Jason Hellenthal's message of "Sun, 8 May 2011 13:39:31 -0400") References: <4DC40E21.6040503@gmail.com> <4DC4102E.8000700@gmail.com> <op.vu2g4b0k34t2sn@tech304> <BANLkTikJgPt4SM_B_7drpgFvO8RkvXaOtw@mail.gmail.com> <201105072231.p47MVktY035491@catflap.bishopston.net> <BANLkTikgnqXB4pdvCd9j9n7pFvg=n5FrdQ@mail.gmail.com> <20110508075203.GA61754@DataIX.net> <BANLkTi=8by=rtbNUDtA8CRSMJsmgPOR2XA@mail.gmail.com> <20110508173931.GA2757@DataIX.net>
next in thread | previous in thread | raw e-mail | index | archive | help
Jason Hellenthal <jhell@DataIX.net> writes: > Chris Rees <utisoft@gmail.com> writes: > > I've updated the docs patches (links at [1]), though unfortunately it > > means it's a little less elegant; I'm reluctant to suggest > >=20 > > # chmod 0700 $D/.. > Haha I would strongly suggest against that ;) Not knowing where people ar= e=20 > keeping the jails would impose quite a bit of harm if they did have them= =20 > in places like that or /var/jailname. What do you mean, "not knowing where people are keeping the jails"? Only root can start a jail, so there is no risk of anyone starting a hidden jail somewhere. Besides, jls(8) lists the root path of each jail. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?86fwoof8lj.fsf>