Re: automatic creation of a chroot environment
Mario Marietto <[email protected]> Thu, 16 Jul 2026 14:22:55 +0200
| Newsgroups | gmane.os.freebsd.devel.hackers |
|---|---|
| Message-ID | <CA+1FSihVVpTnuH8qm6AiRiNHiMAwD5piHknsxbvmNqLbR0s8Fw@mail.gmail.com> |
>Would be this valuable one vermaden is issuing weekly. >URL below is the latest one. >https://vermaden.wordpress.com/2026/07/13/valuable-news-2026-07-13/ I don't see qemu+vmm. Someone knows if it has been reported and where ? thanks. On Thu, Jul 16, 2026 at 2:13 PM Tomoaki AOKI <[email protected]> wrote: > Would be this valuable one vermaden is issueing weekly. > URL below is the latest one. > > https://vermaden.wordpress.com/2026/07/13/valuable-news-2026-07-13/ > > On Thu, 16 Jul 2026 12:18:18 +0200 > Mario Marietto <[email protected]> wrote: > > > ---> Thank You for sharing, I will add this to the next VN. > > > > What's VN ? If I remember correctly, did you also add in your VN the > > project of the virtualization of a Linux/Freebsd vm using qemu > accelerated > > with bhyve / vmm ? > > Can you share the link ? just curious. thanks. > > > > ---> 1. How is that better than 'Service Jails'? > > ---> 2. How is that better than 'Single Process Jails'? > > > > Waiting for the replies to those questions for improving the idea. > Something's > > cooking in my little head, but I don't know what yet.... > > > > Mario. > > > > On Thu, Jul 16, 2026 at 9:09 AM vermaden <[email protected]> wrote: > > > > > Hi, > > > > > > > I've been using chroot for a long time to reduce > > > > the risk of web application hacking on my server. > > > > > > > > Some time ago, I decided it was time to automate > > > > the creation of chroot environments and create a > > > > universal solution for any application/port that > > > > would be easily customizable. > > > > > > > > For simple applications and ports, it usually works > > > > with minimal effort, but for complex ones, it takes > > > > a bit more tinkering. > > > > > > > > The current implementation creates a RO chroot, > > > > without setuid files, with one user and one group. > > > > All RW locations are mounted with noexec and > > > > nosuid. This makes escaping such a chroot > > > > environment extremely difficult, and webshell > > > > and other PHP hacks become impossible. > > > > > > > > I hope someone finds this useful. > > > > > > > > https://github.com/rozhuk-im/chroot_env > > > > > > Thank You for sharing, I will add this to next VN. > > > > > > Two questions out of curiosity ... > > > > > > 1. How is that better then 'Service Jails'? > > > > > > 2. How is that better then 'Single Process Jails'? > > > > > > > > > > https://vermaden.wordpress.com/2023/06/28/freebsd-jails-containers/#single-process-jails > > > > > > Thanks, > > > vermaden > > > > > > > > > > > > > -- > > Mario. > > > -- > Tomoaki AOKI <[email protected]> > > -- Mario.