netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* disablenetwork() syscall?
@ 2003-07-07 19:40 Pekka Savola
  2003-07-07 19:46 ` Jeff Garzik
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Pekka Savola @ 2003-07-07 19:40 UTC (permalink / raw)
  To: netdev

Hi,

In a bugtraq thread, DJ Bernstein brought up an idea which I'm not sure 
has been brought up in the past.  I'm not sure whether it's feasible or 
not, but at least it (and other methods to limit the functions of a 
user-level code) might bear consideration.

-- 
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings
---------- Forwarded message ----------
Date: 4 Jul 2003 23:17:20 -0000
From: D. J. Bernstein <djb@cr.yp.to>
To: bugtraq@securityfocus.com
Subject: Re: Email marketing company gives out questionable security advice

[...]
P.S. It's hard for a portable chroot tool to cut off a program's network
access. Kernel designers should provide a disablenetwork() syscall, with
the disabling inherited by children. Other kernel changes would be nice,
but disablenetwork() is the only critical change.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2003-07-13  7:04 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-07-07 19:40 disablenetwork() syscall? Pekka Savola
2003-07-07 19:46 ` Jeff Garzik
2003-07-07 19:52   ` Pekka Savola
2003-07-07 22:33     ` Arnaldo Carvalho de Melo
2003-07-07 21:03 ` Mitchell Blank Jr
2003-07-07 23:59 ` James Morris
2003-07-13  7:04   ` Pekka Savola

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).