Re: RFC: Network privilege separation.
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2009-01-08 12:09:37
Also in:
lkml
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2009-01-08 12:09:37
Also in:
lkml
Michael Stone [off-list ref] wrote:
In short, I'm trying to provide a general-purpose facility for * limiting networking per _process_, not per user,
You do realise that this is trivial to get around with ptrace, right? So you'll need to stop ptrace as well. Then you'll have to think about all the other ways the process can escape this networking jail because processes belonging to the same user just aren't designed to be separated from each other. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} [off-list ref] Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt