4 ms·
I’ve actually written a short blog post about it (http://khamidou.com/sandboxing/ http://khamidou.com/sandboxing/)! Basically, most of them build a sandbox to
by karim 8y ago
I’ve actually written a short blog post about it (http://khamidou.com/sandboxing/ http://khamidou.com/sandboxing/)!
Basically, most of them build a sandbox to prevent the guest system from interacting in unexpected ways. There’s a bunch of ways you could do this — intercepting syscall, limiting them using seccmp(2), etc.