Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Michael Shigorin                     2:5020/400     28 Sep 2001  11:58:49
 To : "Eugeny A. Krestnikoff"
 Subject : Re: Безопасный хостинг
 -------------------------------------------------------------------------------- 
 
 Eugeny A. Krestnikoff <eugeny@real.kamchatka.ru> wrote:
 
 >> Причем не скажу за chroot vs jail (кто там из jail вылазил у чертей?),
 EAK>А никто не вылазил..... флэйм кончился пшиком.
 
 Ась?
 
 - ---
 On Wed, 18 Apr 2001, Bill Sommerfeld wrote:
 
 >   seteuid(0); a = open("..", O_RDONLY); mkdir("adfa", 555);
 >   chroot("adfa"); fchdir(a); for(cnt = 100; cnt; cnt--)
 >     chdir("..");
 >   chroot(".."); execve("/bin//sh", ..);
 >
 > For the record, I blocked this way of breaking out of chroot in NetBSD
 > in 1999; the fix is present in NetBSD 1.4 and later releases.  I'm
 > surprised that this hasn't been picked up by more distributions.
 
 I expect many many other people are going to reply to this, but here
 goes..
 
 Trying to stop root breaking out of a chroot() environment tends to be
 an exercise in futility. For every escape route you block, a clever
 attacker is likely to think up two more.
 
 Are you claiming root cannot escape a chroot() jail in NetBSD? If not,
 you've increased the complexity of your kernel for little real-world
 gain.  An attacker will know when they are targetting NetBSD, and simply
 modify the shellcode to escape the chroot() in some different manner.
 
 If you _are_ claiming root cannot escape the jail, then how thorough
 have you been? Have you taken care of
 - ptrace() syscall
 - mknod of /dev/kmem
 - mknod of /dev/some_hard_drive
 - attaching to IPC primitives
 - kernel module loading (if NetBSD has the concept)
 - games with mount(), in particular /proc
 - iopl() - if NetBSD has it
 - kill() of a sensitive daemon followed by bind() and then password theft
 - use of a raw network socket to abuse a trust relationship
 - etc. etc.
 
 Cheers
 Chris
 
 - ---
 
 >> но UML в любом случае сделает и то и другое по определению...
 EAK>Угу... слышал про эту фишку, хорошая фишка, только зачем оно здесь?
 
 Как в некоем роде ultimate solution, только практичнее vmware/bochs ;)
 
 -- 
 WBR, Michael Shigorin -- webmaster@www.chem.univ.kiev.ua
 
 >Home Page:  http://visa.chem.univ.kiev.ua/~mike/  ICQ: 113344029
 >Brainbench: http://www.brainbench.com/transcript.jsp?pid=2434729
 
 --- ifmail v.2.15dev5
  * Origin: ~ (2:5020/400)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 Re: Безопасный хостинг   Anton Kovalenko   27 Sep 2001 04:34:13 
 Re: Безопасный хостинг   Eugeny A. Krestnikoff   27 Sep 2001 05:13:02 
 Re: Безопасный хостинг   Michael Shigorin   27 Sep 2001 21:33:05 
 Re: Безопасный хостинг   Eugeny A. Krestnikoff   28 Sep 2001 00:08:24 
 Re: Безопасный хостинг   Michael Shigorin   28 Sep 2001 11:58:49 
 Re: Безопасный хостинг   Ilya Anfimov   28 Sep 2001 21:22:29 
 Re: Безопасный хостинг   Eugeny A. Krestnikoff   01 Oct 2001 10:10:30 
 Re: Безопасный хостинг   Michael Shigorin   02 Oct 2001 19:58:14 
Архивное /ru.linux/76007a4bc8aa.html, оценка 1 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional