From owner-freebsd-questions@freebsd.org Wed Sep 2 19:46:12 2015 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 8AD179C8CDE for ; Wed, 2 Sep 2015 19:46:12 +0000 (UTC) (envelope-from niklaas@kulturflatrate.net) Received: from mail2.kulturflatrate.net (mail2.kulturflatrate.net [IPv6:2a01:4f8:121:52ad::3:1]) by mx1.freebsd.org (Postfix) with ESMTP id 4E142792 for ; Wed, 2 Sep 2015 19:46:12 +0000 (UTC) (envelope-from niklaas@kulturflatrate.net) Received: from [192.168.0.25] (mail.kulturflatrate.net [IPv6:2a01:488:66:1000:2ea3:77dd:0:1]) (Authenticated sender: niklaas@kulturflatrate.net) by mail2.kulturflatrate.net (Postfix) with ESMTPSA id 84C863E48C; Wed, 2 Sep 2015 21:46:10 +0200 (CEST) Subject: Re: Jail causes host to reboot To: Adam Vande More References: <55E6E26A.1040706@kulturflatrate.net> <55E704D4.2050607@kulturflatrate.net> Cc: FreeBSD Questions From: Niklaas Baudet von Gersdorff Message-ID: <55E7526D.5040101@kulturflatrate.net> Date: Wed, 2 Sep 2015 21:47:57 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.2.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Sep 2015 19:46:12 -0000 On 02/09/15 17:11, Adam Vande More wrote: > Yes, depending on configuration. It's trivial to make a jail insecure. > The trick is to make a jail secure and fully functional for your needs. Can you recommend resources that further explicates how to secure jails? I am very interested in this but lack "ideas" on how to attack a system so that I could make it more secure. I'd be happy about any internet resource, book or article. > Yes, but virtualizing is a loaded term. Some people don't consider > jails as virtualization. I do, at least from a certain point of view. > Especially now since independent FS's and network stacks can be > involved. Then you have types like container eg OpenVZ(there was > FreeBSD version of this floating around on 9.x, not sure what happened > to it). The guest in container's have independent kernels so the host > would survive in my original scenario. Same w/ other virtualization > types like KVM, bhyve, VBox, Xen, etc. I also prefer jails. This experience only makes me considering to better secure my jails.