From: Willy TARREAU <willy@w.ods.org>
To: viro@parcelfarce.linux.theplanet.co.uk
Cc: Willy TARREAU <willy@w.ods.org>,
marcelo@conectiva.com.br, linux-kernel@vger.kernel.org
Subject: Re: [RFC][PATCH-2.4] Prevent mounting on ".."
Date: Sun, 29 Jun 2003 16:20:47 +0200 [thread overview]
Message-ID: <20030629142047.GA359@pcw.home.local> (raw)
In-Reply-To: <20030629141102.GE27348@parcelfarce.linux.theplanet.co.uk>
On Sun, Jun 29, 2003 at 03:11:03PM +0100, viro@parcelfarce.linux.theplanet.co.uk wrote:
> On Sun, Jun 29, 2003 at 03:09:52PM +0200, Willy TARREAU wrote:
> > chroot("/var/empty") (read-only directory or file-system)
> > chdir("/")
> > listen(), accept(), fork(), whatever...
> > -> external code injection from a cracker :
> > mount("none", "..", "ramfs")
> > mkdir("../mydir")
> > chdir("../mydir")
> > the cracker now installs whatever he wants here.
>
> That's a BS. Same effect would be achieved by replacing ".." with ".".
> Or mounting on any existing subdirectory.
No, it works only with "..", and not with "." ! I don't know why, I believe
it's because the process is still attached to the old FS when mounting on ".".
> If attacker can mount of chroot - you've LOST. Already. End of story.
To me, it seems this is the *only* remaining case in an *empty* read-only
directory. The fact is that the attacker needs at least a mount point to mount
something. Not providing him one is efficient, but here he can only exploit
"..".
Please reconsider the question, Al, because I really think that with this, we
can get reliable jails for network daemons which don't need file access at all.
Cheers,
Willy
next prev parent reply other threads:[~2003-06-29 14:06 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-06-29 13:09 Willy TARREAU
2003-06-29 14:09 ` Arjan van de Ven
2003-06-29 14:24 ` Willy TARREAU
2003-06-29 14:11 ` viro
2003-06-29 14:20 ` Willy TARREAU [this message]
2003-06-29 14:27 ` viro
2003-06-29 14:35 ` Willy TARREAU
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030629142047.GA359@pcw.home.local \
--to=willy@w.ods.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marcelo@conectiva.com.br \
--cc=viro@parcelfarce.linux.theplanet.co.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®