3 ms·
I would not see this as breaking out of a chroot, because your process already had the file descriptor handle before the chroot system call. Being able to acces
by raimue 7y ago
I would not see this as breaking out of a chroot, because your process already had the file descriptor handle before the chroot system call. Being able to access files that were opened before the chroot call is an intentional feature and used to limit access to a specific set of files.
- davrosthedalek 7y agoNo. The file handle is created after the initial chroot. Then the process chroot again! By fchdir to the file handle, the new AND original chroot are defeated, and a follow up chdir to ../../.. will go to real root.