OpenVZ Forum


Home » General » Support » User ID's and OpenVZ - something you should really consider fixing
User ID's and OpenVZ - something you should really consider fixing [message #21747] Mon, 15 October 2007 20:00 Go to next message
devonblzx is currently offline  devonblzx
Messages: 127
Registered: December 2006
Senior Member
Something I noticed today. I have been running under OpenVZ for a while now and have not run into any main issues but recently I was running commands under a user I made on the main node and when I typed killall -9 process, I thought all was well because it was just a regular user nothing bad should have happened. Little did I know the way OpenVZ reads the user ID's. Apparently when I ran that under my user (user id 501) it killed every single kind of the process in the VPS's who had them running under user ID 501. It was a screen that I killed and I could not figure out why it was happening to this user until I decided to do a ps on the system.

When I ran the "ps ax | grep user" it showed up as my username owning all the processes inside of the VPS's owned by user 501. This means my regular user had access to kill every single process running under that UID inside any VPS.

I guess I had never noticed this before because I don't usually do much with my username on the VPS nodes but this just doesn't seem very secure.


http://static.openvz.org/userbars/openvz-user-2.png
ByteOnSite President
Re: User ID's and OpenVZ - something you should really consider fixing [message #21750 is a reply to message #21747] Mon, 15 October 2007 20:08 Go to previous message
rickb is currently offline  rickb
Messages: 368
Registered: October 2006
Senior Member
http://forum.openvz.org/index.php?t=tree&th=592&mid= 3206&&rev=&reveal=

http://openvz-mirror1.rapidvps.com/contrib/kernel-patches/di ff-ve0-proc-own-processes-only


-------------
Common Terms I post with: http://wiki.openvz.org/Category:Definitions

UBC. Learn it, love it, live it: http://wiki.openvz.org/Proc/user_beancounters
Previous Topic: Unable to start VPS on Debian Etch
Next Topic: Network not working
Goto Forum:
  


Current Time: Fri Sep 27 19:20:10 GMT 2024

Total time taken to generate the page: 0.04346 seconds