Add Comment

You are not currently logged in. If you do not have a user account then please consider creating one and logging in before you post your comment. This will allow you to track replies to your comment, and take part in the site much more freely.

To add your comment, fill in all the boxes below and then preview it to make sure you're happy with the way that it looks.

This is the comment you were replying to, attached to the article Create "chroot jail" for bind:


Re: Create "chroot jail" for bind
Posted by Anonymous (213.211.xx.xx) on Sun 22 Apr 2007 at 20:49
Only processes that are not jailed correctly (for example they have file descriptors open to a directory outside of the jail) or processes that run as root can escape from a jail.

A tool like jk_chrootlaunch from Jailkit can do this for you: close all file descriptors, and change to a non-priviledged user after the chroot but before starting the daemon.

Username:Anonymous
Title:
Your Comment:

Posting Format:

 

Inappropriate comments will be removed.

Some help on entry formatting is available

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search