Chroot Jail

A chroot jail is a sandbox environment on a UNIX system, created using the chroot command. Creating sandboxes for software to run in is an old idea. There are many malicious crackers and worms on the modern day Internet. If a malicious program or intruder is able to gain access to a system and attain root (superuser) privileges, total control over the system is achieved. To gain access to a system, an intruder will attempt to exploit weaknesses in one or several of the programs running on a computer system. An intruder will generally be able to gain the same privileges as the program they successfully exploited. To prevent or slow attackers, or to defend against more typical bugs, administrators may elect to set up a minimal but separate version of their operating system in a separate directory or partition. Programs can then be started in the chroot environment, and any compromise, misrun or crash of those programs will be restricted in impact to that environment. Sometimes a chroot jail is not set up perfectly, usually for reasons of convenience, or by mistake. There is quite some cracker literature devoted to means of breaking out of chroot jails along those lines of weakness.

References

* Jailkit an large set of utilities to build, secure and run your jailed users/daemons/etc.

 

<< PreviousWord BrowserNext >>
chemical abstracts service
maurice bourgs maunoury
mirc game
ultimate players association
canal plus
joseph laniel
ren mayer
list of prime ministers of abkhazia
list of formula one engines
ren pleven
beast wars
henri queuille
cosmography
swedish iron ore during world war ii
andr marie
paul ramadier
paul van dyk
flix gouin
bobby notkoff
fundamental laws of england
rogues gallery
responses of germany and japan to world war ii crimes
fyulaba
pennywise (album)
ellen feiss
lobata
birchfield harriers
return merchandise authorization
gems
jane leeves
edomite language
door to door
chroot
bernard saisset
full count
croc
1998 commonwealth games
battle of indus
bcker b 131
ensemble georgika
steel pulse
operators in c and c plus plus
handsworth revolution
rtbf