IP packets from host system showing inside a jail?
security at revolutionsp.com
Sat Mar 12 06:03:59 PST 2005
I've noticed something odd.. I'm using FreeBSD 5.3-STABLE with PF, on a
dual xeon 2.4 system. I have two jails running for web and mail servers.
Today I was testing something and needed a tcpdump, so inside a jail I
started tcpdump as root.
To my amazement, IP packets from the host system (IRC connections that
should NOT show on that jail) were appearing on the tcpdump INSIDE the
tcpdump then became irresponsive quickly after capturing those, ^C
wouldn't kill it and ^Z didn't nothing either. I had to login from another
terminal to the host system, and killall -KILL tcpdump.
Is this a known bug? IP packets from the host system<->internet should not
be visible inside the jail.
If you need tcpdump/uname -a etc, I'll provide these when asked.
More information about the freebsd-hackers