For those of you not subscribed to src-committers_at_FreeBSD.org, cvs-src_at_FreeBSD.org or cvs-all_at_FreeBSD.org, I just committed a warning note in jail(8) for the security.jail.allow_raw_sockets sysctl MIB about the risks of enabling raw sockets in prisons. Because raw sockets can be used to configure and interact with various network subsystems, extra caution should be used where privileged access to jails is given out to untrusted parties. As such, by default this option is disabled. A few others and I are currently auditing the kernel source code to ensure that the use of raw sockets by privledged prison users is safe. -- Christian S.J. Peron csjp_at_FreeBSD.org FreeBSD committerReceived on Mon May 31 2004 - 15:30:39 UTC
This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:55 UTC