Re: chroot or jail?

2004-04-02 Thread Mark
- Original Message - 
From: "Kris Kennaway" <[EMAIL PROTECTED]>
To: "Mark" <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Thursday, April 01, 2004 10:47 AM
Subject: Re: chroot or jail?

> > Hello,
>
> > I am setting up a new Apache 1.3.29; and I was wondering, should I use
> > jail or chroot to secure it? I know root can potentially break out of
chroot.
> > But what about jail? (FreeBSD 4.9R-p3). Can you break out of a jail?
>
> No [1], that's the point :)

Well, we all know how things are meant to work. I mean, you're not supposed
to be able to break out of a chroot either; yet this is still possible (some
fchdir exploits with open directory file descriptors pointing outside the
chrooted environment). So, I reiterate my question, do such exploits exist
for jail too?

I particularly ask because of the chroot ability of mod_security (1.75). It
chroots Apache, after having started it up. Neat trick. But my suspicious
nature (not necessarily a bait trait in a system administrator) wonders how
breakout-proof that method really is. Especially since Apache keeps quite a
few file descriptors open, pointing outside the chrooted environment. So, I
was contemplating that I am perhaps better off jailing Apache (with a real
jail call), instead of chrooting it.

Cheers,

- Mark

___
[EMAIL PROTECTED] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: chroot or jail?

2004-04-01 Thread Kris Kennaway
On Thu, Apr 01, 2004 at 08:02:04AM +, Mark wrote:
> Hello,
> 
> I am setting up a new Apache 1.3.29; and I was wondering, should I use jail
> or chroot to secure it? I know root can potentially break out of chroot. But
> what about jail? (FreeBSD 4.9R-p3). Can you break out of a jail?

No [1], that's the point :)

Kris

[1] Modulo any implementation bugs, of course.

pgp0.pgp
Description: PGP signature