Walsh: Cool things with SELinux... Introducing sandbox -X
Walsh: Cool things with SELinux... Introducing sandbox -X
Posted Sep 18, 2009 15:02 UTC (Fri) by iq-0 (subscriber, #36655)In reply to: Walsh: Cool things with SELinux... Introducing sandbox -X by PaXTeam
Parent article: Walsh: Cool things with SELinux... Introducing sandbox -X
from doing evil things. What you're talking about is that the application
exploits some weakness in a component outside the sandbox to perform the
evil things for him (or by opening up the containment to let him do it
himself).
I agree that your examples are very harmful and surely need protecting, but
the premise of this sandbox is not that exploitation becomes impossible,
but normal misconduct.
I can write an entirely valid application that does no exploitation
whatsoever but which can really mess up files so that other applications
start misbehaving in new and exciting ways. That is the type of problem
this sandbox deals with: preventing one application from stepping out of
line. Which is also something that fits the sandbox definition.
Both definitions have their place and I see them as additive not one as the
subset of the other.
