FreeBSD Jails

The FreeBSD Documentation Project

Deyan Dyankov

This book describes FreeBSD Jails. It was written for [BG] BSDcon 2005

FreeBSD is a registered trademark of the FreeBSD Foundation.


Table of Contents
����
������ ������������� �����
�������� �������я
�������
1 ���������
1.1 ������
1.2 ���я�� �� Jails (���������)
1.3 ���������� �� ������������
2 �������
2.1 ������
2.2 ����������� �� MySQL
2.3 ����������� �� Apache
2.4 ����������� �� PHP
2.5 ����������� �� MySQL ��������� �� PHP
3 ��������� �� �����������я� �������
3.1 ������
3.2 ��������� �� PHP
3.3 ��������� �� Apache
4 ��������� �� ����� �� jail(8)
4.1 ������
4.2 ������� � ����������
4.3 �����я�� �� ����������� �������
5 �������� � �����������я �� �������
5.1 ������
5.2 ������� ����������
5.3 ������
5.4 chflags(1)
6 ��������� �� /etc/rc.conf/etc/devfs.rules
6.1 ������
6.2 /etc/rc.conf
6.3 /etc/devfs.rules
7 �����������я �� ������, ������я���� �� host ���������
7.1 ������
7.2 sshd
7.3 inetd
7.4 Apache
7.5 MySQL
7.6 named
7.7 ������� ����� �� ������
8 ���������� �� ������� � MySQL �������
8.1 ������
8.2 ���������� �� �������
8.3 ���������� �� MySQL
9 ������� �����
9.1 ������
9.2 ipfw(8)
10 ���������� �� �������
10.1 ������
10.2 ����������/������� �� ������
10.3 ���������� �� ������� � ������
10.4 ������ � �������, ������я���� �� � ������
10.5 ���������я �� �������
11 Other utilities for managing jails
11.1 Synopsis
11.2 sysutils/jailadmin
11.3 sysutils/jailer
11.4 sysutils/jailuser
11.5 sysutils/jailutils
11.6 sysutils/jkill
12 See also
12.1 Synopsis
12.2 jail(8) manpage
12.3 Mike DeGraw-Bertsch
12.4 Jails: Configuring the omnipotent root
12.5 Arch Handbook - The Jail Subsystem

����

������ ������������� �����

���������! ������ ��, �� ���я�я���� ������� ��� ��я�� �����. �� ���� � ������������� �я? ��� ������ ���� ������, ����� ������ ���� �� Apache, PHP, MySQL � ����я��� chroot(8). ���� ����� �������� ������� �� jail(8) - ��������� �� FreeBSD �� �����я�� �� �я�� ������� �����, ��������� � ���� ��������� IP �����. ���� ����������� �� �� ������� �� ��������� "������", � ����� �� ������я��� ����������� ��-���� ������.


�������� �������я

����������� �� �������� �������я: ������� ��� ����������� � ������������� Apache �� ������ �������. �� �� ������я�� � ������������ �� nobody � �������� ������������. ���� � �� �� ��я�� "��������" - ���� ��������� � ��������� �� ������������ �� nobody ����������я�. �я�����, �� � ���-����я� ������ ���������я� ���� �� ������ ����я� ����.

�� �� � ������ ����. ��, ���������я� ���� �� ������ ����я� ����, �� ��� ���� �� ������� ����� ������. ��� ���� �� �������� ���������/������������ ��� ������ �������, �� ����� ����� �� /etc/passwd, �� ���� Apache � �.�. �� ��� ��� ���� �����, �������� ��� "���������" �� ������, �� ���������я� �� �� ����� �� �������� root ������ �� ������ �������.

 

����������� ����� �� ��������� � UNIX, ���:

"���, root, ����� �������?"

 
-- Jails: Confining the omnipotent root.  



�������

�я�� �� �� �� ����������� ��-�����, ��� ���������я�:

  • ������� � ������� �������� ��������?

  • �я�� ������������ �� �������/������ ����я� ����?

  • �я�� ������������ �� �������/������ ������ �����?

  • �я�� ���������� �� �������� ���������/������������ ��� ������ �������?

  • �� ���� �� �� � ����� � ��������я� �� /etc/passwd?

  • �я�� ���������� �� ��������� ����� ������� ������?

  • �� ���� �� ������ ���я� IP ����� �� �������� �� Apache?



����� �����? ����������� � � FreeBSD.


Chapter 1 ���������

� ���� ����� �� ������� �����я�� � ������ ��������, ����� �� ��я��� �� ������.


1.1 ������

���� ���� ��������� ���� ����� �� ������:

  • ����� ����� chroot(8).

  • ���� jail(8) � ��-����� �� chroot(8).

  • �� ����� �� ��������, �� �� ���������.




1.2 ���я�� �� Jails (���������)

��������� �� FreeBSD ���������� ���я�� �� chroot(8). ����������� chroot(8) ������ �� ��������� ����� �� ����������, �� �� ��������� � ������ ���������� �� ������������ �� ������ ������ (/etc, /tmp, /usr, /var, /lib � �.�.). �����я�� �������� ������� (/etc/passwd, /etc/group ..), ������� ���������� � ������ ����������. ������ ��������� ������������ ��� chroot(8) ������������ �����, �� ���� ������������ ��������� � �������� �������.

jail(8) ����� ������ � �я����� ������������ ����:

  • �я���� IP ������� ������ ���� ���� ��������� IP �����.

  • ������� �� �я��� ����������я �� ���� я��� �� ��������� � ������� (���������� root � ������� �� ���� �� ������я IP ������� �� �������, ������я� gateway, ������� �� ��������� �����, �� ���� �� �������� mount(8), ���� �� ����� �������/������� ����� ������� � �.�.)



�������� ������ �����, �� �� � ������? � ����� ������ - ���� ���������.


1.3 ���������� �� ������������

�� �� �������� �� ����� ����� �� �������� ���������� �� ������������:

# export FORCE_PKG_REGISTER=1 (1)
# export J='/usr/jails/web' (2)
               
(1)
���� ���������� ���� FreeBSD �� ��������� ������� �� ports �������я�� ������.
(2)
���� ���������я �� ���� ���������� �� ������� �� �������.

Note: ���� �я�� �� ��������� root �������� ������. ���� �, ������ ��� ��������� :)




Chapter 2 �������

� ���� ����� �� ����������� ���������, ��������� � ������� � ��������������� �������.


2.1 ������

���� ��������� �� ���� ����� �� ������:

  • ��� �� ����������� MySQL, ����������� port ��������� �� FreeBSD.

  • ��� �� ����������� Apache.

  • ��� �� ����������� PHP � ��������� �� MySQL.



����� �� ��������� ���� ����� ��я��� �� ��� ��������� �:




2.2 ����������� �� MySQL

�� ����������� databases/mysql40-server.


cd /usr/ports/databases/mysql40-server (1)
make clean (2)
make install (3)

               


(1)
������� � ���������я�� � ���� �� MySQL's.
(2)
���������� ������ ����� ������������.
(3)
����������� MySQL.



2.3 ����������� �� Apache

�� ����������� www/apache13.


cd /usr/ports/www/apache13
make clean
make install \
CONFIGURE_ARGS='--prefix=/apache --with-layout=FreeBSD --datadir=/apache/www --htdocsdir=/apache/www/data --cgidir=/apache/www/cgi-bin --server-uid=nobody --server-gid=nobody --enable-module=so --enable-module=auth_db --enable-module=mmap_static --disable-module=auth_dbm --enable-shared=max' \ (1)
DOCUMENT_ROOT='/apache/www/data' \ (2)
CGIBIN_ROOT='/apache/www/cgi-bin' \ (3)
PREFIX='/apache' (4)

               
(1)
��я��� �� ������� �я����� ��������� �� ./configure, �� �� ����������� Apache ����, ����� �� ��я���.
(2)
������������ DOCUMENT_ROOT ������ ��� ��� ��������� �� ����я ����.
(3)
���� �� �� ������� .cgi �����������?
(4)
PREFIX � �я�����, ������ �� ����������� Apache



2.4 ����������� �� PHP

�� ����������� lang/php5.


cd /usr/ports/lang/php5
make clean
make install
make install PREFIX='/apache' APXS='/apache/sbin/apxs' (1)

               
(1)
������������ APXS ������ ��� ��� apxs �� Apache.



2.5 ����������� �� MySQL ��������� �� PHP

�� ����������� databases/php5-mysql

���� ���������� �� ���� mysql.so �������. ��� �� �������� �� PHP �� ������ � MySQL ���� �����.


cd /usr/ports/databases/php5-mysql
make install
make install PREFIX='/apache'

               



Chapter 3 ��������� �� �����������я� �������

ApachePHP ���� ����� �� ���� ���������, �� �� �� ������ ������


3.1 ������

���� ��������� �� ���� ����� �� ������:

  • ��� �� �������� PHP �� ������ ������ MySQL ����������.

  • ��� �� �������� Apache ��� ���������� PHP ���������.




3.2 ��������� �� PHP

�� ������������ php.ini, �� �� �������� PHP �� �������� mysql.so

cp /apache/etc/php.ini-dist /apache/etc/php.ini (1)
echo 'extension_dir="/apache/libexec/php"' >> /apache/etc/php.ini (2)
echo 'extension=mysql.so' >> /apache/etc/php.ini (3)
mkdir /apache/libexec/php
cp `find /apache -type f -name "mysql.so"` /apache/libexec/php
               
(1)
php.ini � ���������������я� ���� �� PHP. ��� �������� ������ �� ������������..
(2)
��я��� �� �������� ����������� extension_dirphp.ini, �� �� ����� �� ������� mysql.so.
(3)
��� ������� �� PHP �� ������ mysql.so.



3.3 ��������� �� Apache

�� ������������ httpd.conf, �� �� �������� Apache �� ���������� PHP ���������.


chown -R nobody:nobody /apache (1)
sed -e 's/\/var\/log/\/apache\/logs/' /apache/etc/apache/httpd.conf > /tmp/httpd.conf (2)
mv /tmp/httpd.conf /apache/etc/apache/httpd.conf
sed -e 's/DirectoryIndex/# DirectoryIndex/' /apache/etc/apache/httpd.conf > /tmp/httpd.conf (3)
mv /tmp/httpd.conf /apache/etc/apache/httpd.conf
cat <<END_OF_APACHE_CONF >> /apache/etc/apache/httpd.conf (4)
<IfModule mod_php5.so>
    AddType application/x-httpd-php .php
    AddType application/x-httpd-php-source .phps
</IfModule>
DirectoryIndex index.html index.php
END_OF_APACHE_CONF

               
(1)
����������я� nobody ��� ����� �� ����� �� ������ �� /apache
(2)
������я�� �я��� ���� � ���������������я� ���� �� Apache � ��� �� ���� ������ ������ � /apache/logs ���������я��, ������ /var/log
(3)
��� ������ ������я�� ���������������я� ���� �� Apache. ���� ��� ����������� ����������� DirectoryIndex, �� �� ����� �� я ������� ��-�����.
(4)
���� ��� ������� �� Apache �� ������� ���������, ���������� �� .php.phps ���� PHP ���������. ����, �����я�� ����������� DirectoryIndex, �� �� �������� Apache �� ������� index.phpindex.html, ������ �� ����������� � ���������я.



Chapter 4 ��������� �� ����� �� jail(8)

������ �� ��� �� ��������� ���� ��я� �� ��-����� �� 7 ���? :)


4.1 ������

���� ��������� �� ���� ����� �� ������:

  • ����� �������/���������� �� ������ � ����я� ������.

  • ��� �� �������� ������� �� ������я� ������� ���������� � ����я� ������.




4.2 ������� � ����������

��я��� �� �������� �я����� �����/����������.

mkdir -p $J $J/bin $J/dev $J/etc $J/lib $J/libexec $J/tmp $J/usr/sbin $J/var/log $J/var/run $J/nonexistent (1)
cd $J
touch var/log/console.log (2)
chmod 1777 tmp (3)
cd $J/etc
(4)
cat <<MASTER_PASSWD_END > master.passwd
root:*:0:0::0:0:woot:/nonexistent:/usr/sbin/nologin
nobody:*:65534:65534::0:0:Unprivileged user:/nonexistent:/usr/sbin/nologin
MASTER_PASSWD_END
cat <<PASSWD_END > passwd
root:*:0:0:woot:/nonexistent:/usr/sbin/nologin
nobody:*:65534:65534:Unprivileged user:/nonexistent:/usr/sbin/nologin
PASSWD_END
cat <<GROUP_END > group
wheel:*:0:
nobody:*:65533:
nogroup:*:65534:
GROUP_END
pwd_mkdb -d $J/etc $J/etc/master.passwd (5)
(6)
echo 'nameserver 127.0.0.1' > resolv.conf
echo '192.168.0.13 webjail' > hosts
cp /usr/share/zoneinfo/Europe/Sofia localtime
cd $J
ln -sf dev/null kernel (7)
(8)
cp /bin/sh bin/
cp /usr/sbin/chown usr/sbin/
cp /bin/chmod bin/
cp -R /apache $J (9)
mkdir -p apache/logs
           

(1)
��� ��������� ���������я�� �� ��������.
(2)
��������� var/log/console.log. ���� ���� �� ������� �� /etc/rc.d/jail � �� �������� �� ����� �� ������.
(3)
��я��� �� ������� �������� ����� �� ������ �� tmp/. ����я�� 1777, �������� �� chmod(1) �������� "����� ����� �� ������, ������ � ����������� ��: ����������, ����� �� ����������, ������ �������� � ���� ����� 'sticky bit'". sticky(8) ����� ����� ���������я�� ���������. ������ ��� � ������� - �����, ����� ��� ������� ���������� �� ���������я�� ���� �� ������� �������/����������, �� �� ����������, ��� �� �� ������я�� ��� ��� � ����� ����������. ���� ������ ���������я�� � o+rwx, �������� �� ����������я� � ��������� ���� �� ���� �������, ����� ��� ���������.
(4)
��� ��������� ��������� /etc/passwd, /etc/master.passwd/etc/group, ����� �� �������� �� ���������. �����я�� ���� rootnobody �����������, ������ �я���� ����� �� �����.

Note: ��������, �� �������� �я���� ����� �� root ����������. ����� �� ���������� �������� ��� ����, ��.. /etc/rc.d/jail �������� ��������, ����������� -U root ����я��, ���� �� ��я��� �� ������� � ���� ����������. ��� ��� �������� - ������ �� ���������� rootwheel �� passwd, master.passwd, group ���������. � ����� ������ �� �� ������ �� ���������� -U root �� /etc/rc.d/jail.

(5)
���� ���� ���� ����������� � passwd, master.passwdgroup � �������� ��я��� �� ����������� pwd_mkdb(8), �� �� �������� etc/pwd.db
(6)
��������� � �������� �� ��������� � DNS ������ - ��я�� �� �� ������ � /etc/resolv.conf. ������я� DNS ������ � 127.0.0.1, �� ������ �� �� �������, ������� ��. ������ /etc/hosts �� � ������������, �� ���� �� ���� ������� � PHP �����������. �� �� ����������� � ����� ����� ��я��� �� ��������� /etc/localtime. ��� ���������� /usr/share/zoneinfo/Europe/Sofia, ������ �� ����я ����� �� Sofia :) ������� ��, ��я��� �� �������� ������, ����� �������я �� ������ ������ ���� � /usr/share/zoneinfo.
(7)
jail(8) �����, �� ��я��� �� �������� ���� ���������� ������ :)
(8)
�����я�� sh(1), chown(8)chmod(1), �� �� ����� �� �������� ������� �� ������ ������ �������� �������� � ���������� �����.
(9)
�� �� ������я�� /apache, ������ �� ���� �я���� ����я.



4.3 �����я�� �� ����������� �������

����я� ��я� ��� ����� �� �я� ;)

cd $J
cp /libexec/ld-elf.so.1 libexec/ (1)
cp /var/run/ld* $J/var/run (2)
(3)
ldd -a `find /apache -not -type d` 2>& /dev/null | grep -v ':$' | awk '{print $3}' | sort | uniq > /tmp/reqlibs
ldd -a /bin/sh 2>& /dev/null | grep -v ':$' | awk '{print $3}' >> /tmp/reqlibs
ldd -a /usr/sbin/chown 2>& /dev/null | grep -v ':$' | awk '{print $3}' >> /tmp/reqlibs
(4)
while read f
do
    d=`dirname $f`
    mkdir -p $J$d
    cp $f $J$d
done < /tmp/reqlibs
rm -rf /tmp/reqlibs (5)
           

(1)
ld-elf.so.1 � �. ���. "dynamic linker". ��� �������� /var/run/ld-elf.so.hints/var/run/ld.so.hints, �� �� ���� �� ������ ���������� ���� �� ������ ������������, �� ����� ��� �����.
(2)
������� �� ����� ������� ld-elf-so.1? �������� ����� �������, ����? �, ����� ���� ������� ���� �� ��я���� :)
(3)
ldd(1) ��������� ������������, �� ����� ������ ���������� �� ������. ��� �� ����������, �� �� �������� ��� ���������� �� ����� �� ��������� � /apache, /bin/sh, /usr/sbin/chown, ��� ���� ����� ��������� �� �� ����������. �������� �������� ����� /tmp/reqlibs � �� ����я� � ���������������� �� ���� ����������.
(4)
���� ����� ����� ������� /tmp/reqlibs � ������ ������������ � �������.
(5)
/tmp/reqlibs �� ������ ��������, ���� ����� ��������� �� ���� ������..



Chapter 5 �������� � �����������я �� �������

������ ���������� �� �������� � ��� �����������я.


5.1 ������

���� ��������� �� ���� ����� �� ������:

  • ��� �� ���������� ������.

  • ��� � ������� � ��� �� �� ����������.

  • ��� ������� �������� ����� �� ������������. (����������� chflags(1))



����� �� ��������� ���� �����, ����я�� �� ������ �� ����������:




5.2 ������� ����������

��� ��� ����� �� ���������� ����я� ������:

jail $J testapache 192.168.0.13 /bin/sh (1)
chown -R nobody:nobody /apache
cd /apache
chmod -R 500 * (2)
chmod -R 600 logs (3)
exit (4)
               
(1)
���� ��� �������� �������. ��� �������� $J, �� �� ���� �� ��������� ���� � �������� ���������я �� ����я� ������. �� ������ �� ���� ���� �� ���������� ����� testapache. ��я��� �� ������� IP �������. ���� � IP �������, ����� �� �� �������� �� �������. /bin/sh �� ���� ��������� �� jail(8), �� �� ����� �� ������� ��������������� �������.

Note: IP �������, ����� �� ���������� ��я��� �� �� �������� �� ���������. ������ �� ���������� 127.0.0.2 �� ������я �����:


ifconfig lo0 alias 127.0.0.2 netmask 255.255.255.0

                                   


(2)
������� ������ �������/���������� � /apache ������ � ��������� ���� �� �����я� ���������� (nobody).
(3)
������� ������ �� ������ �� /apache/logs �� nobody. Apache ���� ���� �� ������� ������ ��� �������.
(4)
����� �� ��������� �� �������, ���� �� � �� ����� � ��������я� shell.



5.3 ������

����� ������������ �� ��������� �я��� �������/���������� �� �������:

cd $J
unlink apache/www/data
mkdir apache/www/data
rm -rf bin/sh usr/sbin/chown bin/chmod apache/www/data-dist etc/passwd etc/master.passwd (1)
(2)
cat <<END_OF_TEST > apache/www/data/index.php
<?php
if(mysql_connect(":/tmp/mysql.sock", "root", "")) echo("You have successfully configured Apache, PHP and MySQL :)");
?>
END_OF_TEST
           

(1)
�� ������� ������, ����� ���� �� � ����������.
(2)
��������� index.php, ����� ����� �� ���������� �� ���� �� Apache, PHP, � MySQL. ���� � ������, ����� ��������я�� ������ � MySQL ������ ����� ���� socket (/tmp/mysql.sock), ���� ����� ������� ��������� ��� �����.

Note: ������ ����������� PHP ����������, ����� �������� MySQL ���� ����� ��я��� �� ��������� :/tmp/mysql.sock, ������ ������ ������� �� MySQL hostname. ����������� ���� ������ ������ �� ������� IP ������� �� ������ host �������.




5.4 chflags(1)

������ �я��� ������� �� �������:

chflags -R schg,sunlnk apache bin etc lib libexec usr var/run/ld* nonexistent (1)
chflags -R noschg,nosunlnk,sappend apache/logs (2)
chflags -R noschg,nosunlnk apache/www (3)
               
(1)
������ "system immutable" (schg) � "system undeletable" (sunlnk) ������� �� ������������. ��������� chflags(1) �� ������ ���������я.
(2)
������� ������� ������� �� apache/logs � ������� �� Apache �� ������� ������ ������. ����� "system append-only" (sappend) ������� �� ���� �������. ���� ��������, �� ���� ������� �� ����� �� ����� �������/������������, ����� ��� ��������� �� �� -��������- ��� ���������. �� ������ ���������я �������� �������� �� � ���я�� -f �� tail(1).
(3)
������� "system immutable" � "system undeletable" ��������� �� apache/www. ���� � ���������я��, ������ Apache ���� ��������� �� ���������. � ������� � ��������� � �����������я �� Apache. ��я��� �� ��������� ���� �������, �� �� ����� �� �������� ���� ������� � ��������� �� ����я� ����. ���� ����� ��я��� �� ������� ���������, �� �� ����� ���������я� �� ������я/������� ���� �����.



Chapter 6 ��������� �� /etc/rc.conf/etc/devfs.rules

�� �� �� �������� ����я ������ ����������� ��я��� �� ������� �я����� ���� � /etc/rc.conf/etc/devfs.rules


6.1 ������

���� ��������� �� ���� ����� �� ������:

  • ����� ��я��� �� ������� � /etc/rc.conf, �� �� �������� ��������� ����������� �� �������� �������� � MySQL ��������.

  • ����� ��������������� ����� �� ������� �� �������.

  • ��� �� ������я�� devfs(8) ��������� � �������.



����� �� ��������� ���� ����� ����я��� �� ������ �� ����������:




6.2 /etc/rc.conf

��я��� �� �������� IP ��������, �������� � MySQL �������. �� ���� ��� ��я��� �� ������� �������� � /etc/rc.conf

(1)
ifconfig_fxp0="inet 192.168.0.2 netmask 255.255.255.0"
ifconfig_fxp0_alias0="inet 192.168.0.13 netmask 0xffffffff"
(2)
mysql_enable="YES"
mysql_args="--bind-address=127.0.0.1 --socket=/usr/jails/web/tmp/mysql.sock"
(3)
jail_enable="YES"
jail_list="web"
jail_set_hostname_allow="NO"
jail_socket_unixiproute_only="YES"
jail_sysvipc_allow="NO"
jail_getfsstatroot_only="YES"
jail_allow_raw_sockets="NO"
jail_chflags_allowed="NO"
(4)
jail_web_rootdir="/usr/jails/web"
jail_web_hostname="web"
jail_web_ip="192.168.0.13"
jail_web_exec_start="/apache/sbin/httpd"
jail_web_exec_stop=""
jail_web_devfs_enable="YES"
jail_web_devfs_ruleset="webjail"
jail_web_mount_enable="NO"
           

(1)
����я��� ����������� � ����я� ���, �� ��я��� �� ��������� ������� �������. ��������� IP �������, ����������� � ��������� �����. ��� �����я� ��� ��я��� �� ��������� IP ������� �� jail(8). (� �����������;)
(2)
�����я� ��� �������� MySQL. �����я� �����я ��� ��������� ��� ��������� mysqld_safe. �� ����� MySQL �� ������ ������ ���� �� 127.0.0.1 � �� ������� ���я� socket ��� /usr/jails/web/tmp ������ � /tmp. ���� �� ������ �� ������� IP ������� �� ������ host �������. ����я��� �� ������ �� �������� "alias mysql='mysql --socket=/usr/jails/web/tmp/mysql.sock'" ��� ����я� .bash_profile ��� start-up ������� �� ����������я� �� ��� shell.
(3)
  • jail_enable: ��������� ��������� ��� ���������� �� ���������.

  • jail_list: ������ ��� �������, ����� ��я��� �� ����� ����������. � �������� �������я ����� ���� ���� ������, ������� "web".

  • jail_set_hostname_allow: �� ����� �� ��������� ������� �� hostname � �������?

  • jail_socket_unixiproute_only: �������� ����������� �� UNIX/IPv4/route ������ � �������?

  • jail_sysvipc_allow: ����� �� ��������� � ������� �� ��������� System V IPC primitives?

  • jail_getfsstatroot_only: ��������� ������ ���� �я����� root ������� ������� � getfsstat()

  • jail_allow_raw_sockets: �� ����� �� ��������� � ������� �� �������� "raw" ������?

  • jail_chflags_allowed: �� ����� �� ��������� � ������� �� ������я� ������� �� �������?

    Note: jail_chfalgs_allowed � �������� ��� FreeBSD 5.4



(4)
  • jail_web_rootdir: ���� � ������� �� ��������? (������� �� ������������ $J?)

  • jail_web_hostname: ����� �� �������

  • jail_web_ip: IP ������� �� �������

  • jail_exec_start: ���������, ��я�� ��я��� �� �� �������, �� �� �� �������� �������. � ����я� ������ ��я��� �� ���������� Apache, ����������� /apache/sbin/httpd

  • jail_exec_stop: �я���� ����� �� ����, ������ /etc/rc.jail ������� -TERM ������ ��� Apache ����� -KILL. �� ���� ����� Apache ���� �� ������� �������� ��, �� ������� ������ ������� ������, �� ������ �������� � �� �� ���� ������������;)

  • jail_devfs_enable: devfs(8)/dev ?

  • jail_devfs_ruleset: ��� ��������� /dev - ��� ������� �� ����������?

    Note: �� �� �������я�����, ��������� �� ����� ��������� � ���������� �����я.



  • jail_web_mount_enable: ������� ������������ �� mount(8) ������� � �������?




6.3 /etc/devfs.rules

��я��� �� ����� �я����� �������, ����?

�������� �������� � /etc/devfs.rules

[webjail=13] (1)
add hide (2)
(3)
add path null unhide
add path 'net' unhide
add path 'net/*' unhide
add path 'net?' unhide
add path 'fd' unhide
add path 'fd/*' unhide
add path 'std*' unhide
add path 'random' unhide
add path 'urandom' unhide
add path 'zero' unhide
           

(1)
����� � �������������� �� ������ ������� (jail_web_devfs_ruleset/etc/rc.conf). ���� �� �� ������ �� �� ������� (13).
(2)
����� ������ ����������.
(3)
������ �я��� ����� ����������.



Chapter 7 �����������я �� ������, ������я���� �� host ���������

��������, ������я���� �� host ��������� ���� ��я��� �� ����� �������������. ��������, ��� ������я���� sshd(8) - ��я��� �� �� ������������� ����, �� �� ������ ������ ���� �� ������ �� host ���������. ��� �� ������� ������� ������ �� ������������� �� �я��� ������.


7.1 ������

���� ��������� �� ���� ����� �� ������:

  • ��� �� �������� sshd(8) �� ������ ������ ���� �� host ���������.

  • ��� �� �������� inetd(8) �� ������ ������ ���� �� host ���������.

  • ��� �� �������� Apache �� ������ ������ ���� �� ��������� IP �����.

  • ��� �� �������� MySQL �� ������ ������ ���� �� host ���������.

  • ��� �� �������� named(8) �� ������ ��я��� �� ��������� ������ �� IP ������.

  • ��� �� ��������� ��я��� ��� ������, ����� �� ��������� ������� ����� �� �����������я ����������� ������� �����.




7.2 sshd

�� �� ��������� ���� ��� �� ������ �� ������������ /etc/ssh/sshd_config. ���������������я� ���� �� ������������ ��� ����������� ����я, �������� ListenAddress � �я �������� �� ������я� �����:


#ListenAddress 0.0.0.0

               


������ ���� ����я � ����������� sshd(8) ������ ������ �� ����� IP �����. �������� ��я��� �� ��������� ��������� � �� �������� ������ ��������:


ListenAddress 192.168.0.2

               


� ���� ������ 192.168.0.2 � ������� �� ������ host �������. ��� ��я��� �� �� ��������, ����������.

���� ����я�� �� /etc/ssh/sshd_config ��я��� �� ������������ sshd(8):


/etc/rc.d/sshd restart

               



7.3 inetd

inetd(8) ���� ������ ������ �� ����� IP �����. �� �� �������� ���� �������� ��я��� �� ������� ������я� ��� � /etc/rc.conf:


inetd_flags="-wW -a 192.168.0.2"

               


���� ��я��� �� ������, �� �� ������ �� ��������� 192.168.0.2.

���� ����������я �� /etc/rc.conf � ����������� ������������ �� inetd(8):


/etc/rc.d/inetd restart

               



7.4 Apache

Apache �� ����� �� ����я� �����. �� �� �� �������� �� �������� ���� ���� IP ����� ��я��� �� �������� httpd.conf. �������� ����������� Listen. ��� ��� ������ �� ���� Listen directives - ������������ �� � �� ��������� ��� ��������:


Listen 192.168.0.2:80

               


���� �� ������ Apache �� �������� ���� ���� 80 �� ������ host �������. ���� ����������я �� httpd.conf �� ������ ������������ �� Apache:


apachectl restart

               


��� ��� ����������� Apache ����������� ports/packages ������, ����� ��я��� �� ��������� � /etc/apache/httpd.conf � ������ �� ������������ ������� ��� �������� �������:


/etc/rc.d/apache restart

               



7.5 MySQL

����я�� ���������� �� MySQL ���� � ����� ������. ��я��� �� �������� --bind-address ����я�� �� ��������� mysqld_safe. ��� ���� ������:


mysqld_safe --bind-address=192.168.0.2

               


��� ��� �������� ������������ � ��� ����������� MySQL �� FreeBSD port ��������� ��я��� �� �������� ���� ��� � /etc/rc.conf, �� ��� ���� ��������� ���� � �������� �����.


7.6 named

���������������я� ���� �� named(8)/etc/namedb/named.conf. ��� ��я��� �� ��������� ����я�� listen-on � �� �������� IP �����, �� ����� named(8) �� ������ ��я��� (��� ������ �� IP ������)

�� ������������ ���� ��� �������� ����:


listen-on   { 127.0.0.1; }

               


��� ���� � �����я� - named(8) ����� ���� �� 127.0.0.1 � �я�� ����� �� ����я��.


7.7 ������� ����� �� ������

�����я�� �� ������� ����� �� ���� ����������� ������ ��� �� �������� ������, ����� �� ��������� ������� �����������. ���� �� ������� ���� �� ���������я ������ ���� �� 80�� ���� �� IP ������ �� �������. ������ ������ �� ����я� IP ����� �� �������� ������� ��������� TCP RST (“Connection Refused”).

������ ����, �� �� �������� ���������я�. ������ ��� ������ TCP RST - ���������я� ������ �� �������, �� �� ������я ����� ������� �����.


Chapter 8 ���������� �� ������� � MySQL �������

��� ��� �� ���������� ����я� ������ � MySQL ������ ��� ������������ �� �я���� �������


8.1 ������

���� ��������� �� ���� ����� �� ������:

  • ��� ����� �� �������/������ ������.

  • ��� ����� �� �������/������ MySQL �������.




8.2 ���������� �� �������

������ �..

/etc/rc.d/jail start
           

8.3 ���������� �� MySQL

����� �����, ������ � :)

/usr/local/etc/rc.d/mysql-server.sh start
           

Chapter 9 ������� �����

�������� ������


9.1 ������

���� ��������� �� ���� ����� ��� �� ������ ��:

  • ��������� ipfw(8) ������� �� ����я� ������.



����� �� ��������� ���� ����� ����я��� �� ������ �� ����������:

  • http://freebsd.org/doc/handbook/firewalls.html




9.2 ipfw(8)

���� �������� ������ �������� ipfw(8)

#!/bin/sh
cmd="/sbin/ipfw -q add"
out="fxp0" (1)
real_ip="192.168.0.2" (2)
jail_ip="192.168.0.13" (3)
ks="keep-state"
/sbin/ipfw -q -f flush (4)
$cmd 1000 allow all from any to any via lo0 $ks (5)
(6)
$cmd 1001 allow tcp from me to any 53 out via $out setup $ks
$cmd 1002 allow udp from me to any 53 out via $out $ks
$cmd 1003 allow all from any to me 22 $ks (7)
$cmd 1004 allow all from $real_ip to any out via $out setup $ks uid root (8)
$cmd 1005 allow tcp from any to $jail_ip 80 via $out setup $ks (9)
(10)
$cmd 1006 reset all from any to $jail_ip via $out
$cmd 65534 deny log all from any to any
           

(1)
���� � �����������, ����� �� �������� �� ������ ������� �� ������ � ������я� ��я�. ����я��� �� �� ������ �� �� ���������.
(2)
���� � IP ������� �� ������ ���� �������. �� �� ������ �� �� ���������.
(3)
���� � IP ������� �� ����я� jail(8). �� �� ������ �� �� ���������.
(4)
��������� ������ �������� �������.
(5)
������� ������ ������� ������ ���� (lo0) �����������.
(6)
���������� �� DNS �������.
(7)
������� ssh(1) ������ �� host ���������.
(8)
�� ����������� root ����������я.
(9)
������� ������ ���� �� 80�� ���� ��� �������.
(10)
����� RST �� ����� ���� �� ������ ��� $jail_ip � �� ������� �������� �� ������ ����� ������.



Chapter 10 ���������� �� �������

���� ����� �� ����� �������� �� ������������ �� FreeBSD ���������.


10.1 ������

���� ��������� �� ���� ����� �� ������:

  • ��� �� ����������/������ ������.

  • ��� �� ��������� ������� � ������.

  • ��� �� ��������� ��� ������� �� ������я��� � ������.

  • ��� �� �� �������� � ���������я ������� ���������� �������.




10.2 ����������/������� �� ������

�������� �� �я�����:

�� �� ���������� ������ ���� ������ ��я��� �� ���������� ��������� jail(8). ����� �� �������� ���������:

  • path - ��� ��� �������.

  • hostname - ��� �� �������.

  • ip-numer - IP ����� �� �������.

  • command - �������, ��я�� �� �� ������� (�������� /bin/sh)



�� �� ������ ����� ���� ������ ��я��� �� ���������� killall(1). ������:


killall -j 1

               
������ 1 � ��������������� �� �������. (������ ���������я �� ��������������� - ���� �����)

�� �� ����������/������ ���������� ���� ������ ������ �� ���������� /etc/rc.d/jail. �� �� ��������� ���� ����� ��я��� �� ������� ��������������� ����� � /etc/rc.conf. ���� ���������� ����, ���� �� �������� ������ �� ���������� /etc/rc.d/jail start/stop.


10.3 ���������� �� ������� � ������

������ �� ���������� jexec(8), �� �� ��������� ������� � ������. �я ������ ��� ���������:

  • jid - ������������� �� ������

  • command - ����� ��� �� ���������




10.4 ������ � �������, ������я���� �� � ������

���я � ������� �� ������ ��� ������� �� ������я��� � ������. ������ �� ���������� ps(1), �� �� ���������.

������:


ps auxww | grep 'J'

               


��� �������� �� ������я�� � ������, �� ��� ��� 'J' ���� � STAT. ����������� 8���� ������ �� ������ �� ps(1). ��� ��� 'J' - �������� � � ������.

���� ����� �� ��������� ��� ������� �� � ������ � �� ���������� jps - �������� �� ����� sysutils/jailutils.


10.5 ���������я �� �������

������ �� �� �������� � �я���� ���������я, ��я�� �� ��я���, ����������� jls(8). ������:


# jls
JID  IP Address      Hostname                      Path
  1  192.168.0.13    web                           /usr/jails/web

               


�������� JID � ��������������� �� �������. ���� ������������� �� �������� �� ����я�� -j �� killall(1)'s -j, ��������� jexec(8) � �������� ������� �� ������ sysutils/jail* (���������� �����).


Chapter 11 Other utilities for managing jails

Sometimes the default FreeBSD utilities for managing jails are not enough. Here are described some packages that you might want to use.


11.1 Synopsis

After reading this chapter you will:

  • Know something more about the available utilities for managing jails.




11.2 sysutils/jailadmin

sysutils/jailadmin is a system for managing a set of named jails.

It is designed to provide more flexible functionality than FreeBSD's own /etc/rc.d/jail script and provides the following features:

  • A command line utility for starting and stopping named jails.

  • An efficient method for shutting down a large number of jails in parallel.

  • A simple configuration syntax.

  • SNMP monitoring facilities.



I have never used this utility but you might want to play with it. The SNMP monitoring sounds good.


11.3 sysutils/jailer

This utility must be installed inside the jail and has the ability to shutdown/restart it.

I haven't used this utility because calling /etc/rc.d/jail start/stop does the same thing. Besides ..jailer creates its own process inside the jail and if an attacker gains nobody's privileges he is able to list the processes and see that he's actually into a jail.

Anyway, the injail command in this package looks interesting. It determines if a process is running inside a jail and might be used for scripting purposes.

Another way to determine if a process is running in jail is to parse the output of ps(1)


11.4 sysutils/jailuser

This utility builds a chrooted environment. The same thing we did in chapter 4. Its main goal is to create a list of proper libraries to be copied and create the environment.

We haven't used this utility because our task was simple and didn't require such tools.

If you want to create a fat jail environment with all the tools/programs you need - consider reading jail(8) It has a wonderful example.


11.5 sysutils/jailutils

This package has some neat utilities that can be used for scripting purposes.

  • jps - List processes in jail

    Note: In order this to work you need /bin/ps in the jail's directory tree.



  • jid - Print id of jail

  • jails - List running jails.

  • injail - Determine if a process is running in a jail.



It also has some other utilities for starting/stopping jails. If you want more information - install the package :)


11.6 sysutils/jkill

This package has only one application, called jkill.

It shutdowns a running jail and all its processes.

Anyway, you can achieve the same thing (and even more) with /etc/rc.d/jail stop


Chapter 12 See also

12.1 Synopsis

After reading this chapter you will:

  • Know where to find some more articles about FreeBSD jails.




12.2 jail(8) manpage

The jail(8) manual describes a way of creating a fat jail. The whole idiea is to rebuild your world and put -anything- you need inside the jail environment. This allows you to run all kinds of services, including sshd(8) which could help you with the administration.


12.3 Mike DeGraw-Bertsch

Mike DeGraw-Bertsch has written a wonderful article which expands jail(8)

You can find it at http://www.onlamp.com/pub/a/bsd/2003/09/04/jails.html


12.4 Jails: Configuring the omnipotent root

A paper by Poul-Henning Kamp and Robert N. M. Watson /usr/share/doc/papers/jail.ascii.gz


12.5 Arch Handbook - The Jail Subsystem

The jail susbsystem is explained.. in the Arch-Handbook


This, and other documents, can be downloaded from ftp://ftp.FreeBSD.org/pub/FreeBSD/doc/.

For questions about FreeBSD, read the documentation before contacting <[email protected]>.
For questions about this documentation, e-mail <[email protected]>.