[ronvdaal@zarathustra.linux666.com: Possible security issue with FreeBSD 5.4 jailing and BPF]

Simon L. Nielsen simon at FreeBSD.org
Thu Jul 14 16:52:53 GMT 2005


On 2005.07.14 09:26:56 -0700, Avleen Vig wrote:
> This message was sent to bugtraq today:

Please see the thread on full-disclosure as to why this is not an
issue.

http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/035036.html

Unfortunately the poster sent separate mails to full-disclosure and
bugtraq, so the followups where only set to full-disclosure (since we
saw the mail first there).

> While playing around with FreeBSD 5.4 and jailing I discovered that it was
> possible to put an ethernet interface into promiscious mode from within the
> jailed environment, allowing a packetsniffer to gather data not meant for
> the jailed box. This also affects FreeBSD 5.3 (tested) but not FreeBSD 4.x 
> This can be reproduced on boxes where BPF support is enabled in the kernel 
> and a BPF device is available in the jail (badly configured devfs/no rules)
[...]

-- 
Simon L. Nielsen
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-security/attachments/20050714/73650b13/attachment.bin


More information about the freebsd-security mailing list