Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 8 May 2011 03:52:03 -0400
From:      Jason Hellenthal <jhell@DataIX.net>
To:        Edho P Arief <edhoprima@gmail.com>
Cc:        Jamie Landeg Jones <jamie@bishopston.net>, freebsd-security@freebsd.org, feld@feld.me, utisoft@gmail.com
Subject:   Re: Rooting FreeBSD , Privilege Escalation using Jails (P??????tur)
Message-ID:  <20110508075203.GA61754@DataIX.net>
In-Reply-To: <BANLkTikgnqXB4pdvCd9j9n7pFvg=n5FrdQ@mail.gmail.com>
References:  <4DC40E21.6040503@gmail.com> <4DC4102E.8000700@gmail.com> <op.vu2g4b0k34t2sn@tech304> <BANLkTikJgPt4SM_B_7drpgFvO8RkvXaOtw@mail.gmail.com> <201105072231.p47MVktY035491@catflap.bishopston.net> <BANLkTikgnqXB4pdvCd9j9n7pFvg=n5FrdQ@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--8t9RHnE3ZwKMSgU+
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable


Edho,

On Sun, May 08, 2011 at 09:15:28AM +0700, Edho P Arief wrote:
> On Sun, May 8, 2011 at 5:31 AM, Jamie Landeg Jones <jamie@bishopston.net>=
 wrote:
> >> All the same, I've sent a PR [1] with some doc patches to make people
> >> more aware of this -- fulfilling my promise of 2+ years ago :S
> >>
> >> Thanks!
> >>
> >> Chris
> >>
> >> [1] http://www.freebsd.org/cgi/query-pr.cgi?pr=3D156853
> >
> > Um. Some problems here.
> >
> > A jail won't work for not-root users if the jail root directory is chmo=
d 700 - although
> > there is obviously a 'chroot' running withing the jail, the jailed user=
 still needs
> > to have read permission from the hosts / -- chmod 700 therefore locks a=
ll non-root
> > users out.
> >
>=20
> It's weird - I don't remember having such problem after setting jails'
> root directory permission to 700. I don't have the system anymore so I
> can't verify it just yet.

It should also be noted here that the jailed root user also has permission=
=20
to chmod(1) '/' to anything he or she wants unless you have taken=20
precaution to not allow that. I would reccoment storing your jails two=20
levels deep into a directory and chmod(1) 700 the first level to prevent=20
access from the host and from the jailed root user changing the perms.

--=20

 Regards, (jhell)
 Jason Hellenthal


--8t9RHnE3ZwKMSgU+
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (FreeBSD)
Comment: http://bit.ly/0x89D8547E

iQEcBAEBAgAGBQJNxkuiAAoJEJBXh4mJ2FR+/1wH/2jhRwdIdWNWL4znJnN0j2H7
eOEeCZHzs80S1v4lEug+6Ka/XLU0ag4N1dDCOkU3FzP5tptM9pCx6LHjsJa57pkv
nJZWAz5e9khRKzv3F55wYBHlY5sD9zb64Tf2NpeTLvT+T4C3MvLY3ju2jVlShQcN
ZsFeSyvMb2t/t7ADWP4x/fyWvQDs05edPyDMR3ipKUeje5DIV5tL/DAVg0cBefix
3PINhW17rxXrWsvyxwTrshtHfwYLzuUoF0Lnj7KUKw1gE7n7H5eobmllMvvzZZ/7
lmrRCjdWiMLTdKgqPxPMSX5lzjwnCoaYVC/+Lw4o5sWL4/lqYD81vLXzx+6OFA0=
=ZjGb
-----END PGP SIGNATURE-----

--8t9RHnE3ZwKMSgU+--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20110508075203.GA61754>