Re: [zones-discuss] Possible to use zones for hardening? Security?

2010-11-26 Thread Orvar Korvar
petrben, Yes that is my question too: is running in a local zone safer?. That is why I created this thread. I was thinking something like this: If someone hacks my WinXP, then he must bypass VBox. Then he is inside the local zone. Then he must get root access to the local zone. Then he must

Re: [zones-discuss] Possible to use zones for hardening? Security?

2010-11-26 Thread Paul van der Zwan
On 26 Nov 2010, at 10:50 , Orvar Korvar wrote: petrben, Yes that is my question too: is running in a local zone safer?. That is why I created this thread. I was thinking something like this: If someone hacks my WinXP, then he must bypass VBox. Then he is inside the local zone. Then he

Re: [zones-discuss] Possible to use zones for hardening? Security?

2010-11-26 Thread Petr Benes
On 26 November 2010 10:50, Orvar Korvar knatte_fnatte_tja...@yahoo.com wrote: petrben, Yes that is my question too: is running in a local zone safer?. That is why I created this thread. Yep and I found your question interesting and want to know more as well. If you are the only administrator

Re: [zones-discuss] Possible to use zones for hardening? Security?

2010-11-26 Thread Orvar Korvar
If hacker exploits a bug in the VBox driver and corrupts kernel memory so he gets into the global zone, then maybe it is safer to not use VBox? And only use local zones for reaching the outside world? And shutdown the NIC to the global zone? -- This message posted from opensolaris.org

Re: [zones-discuss] Possible to use zones for hardening? Security?

2010-11-26 Thread Petr Benes
On 26 November 2010 13:25, Orvar Korvar knatte_fnatte_tja...@yahoo.com wrote: If hacker exploits a bug in the VBox driver and corrupts kernel memory so he gets into the global zone, then maybe it is safer to not use VBox? If such bug exists then it'll be safer to not use VBox, however, I'm not

Re: [zones-discuss] Possible to use zones for hardening? Security?

2010-11-26 Thread Pete Chan
how can I ssh into a local zone if the global zone has no outside connection?? you have 2 options. 1. from the global you can simply use zlogin zonename and ur in. 2. you can add tcp wrappers to the non-global zone to only allow ssh connections from the global. Date: Fri, 26 Nov 2010