Subject: Re: Escaping a chroot jail
To: Edgar Fu? <efnbl05@bn2.maus.net>
From: Thor Lancelot Simon <tls@rek.tjls.com>
List: tech-security
Date: 07/13/2005 17:34:39
On Wed, Jul 13, 2005 at 11:13:16PM +0200, Edgar Fu? wrote:
> I discussed this with Wolfgang Solfrank last week, and he suggested
> I might communicate it to the security officer, who in turn suggested
> discussing it here:
> 
> Is everybody aware of the fact that you should be able to escape a chroot jail
> (given root privilleges and the ability to execute arbitrary code) simply
> by doing a mknod() for the root file systems raw device inside the jail
> and then emulating the file system?

"Emulating" the file system?

Thor