Fakecracker: NetBSD as a Function Based MicroVM
imil.net
imil.net
The link seems to be down, I found this as a replacement http://197.155.77.5/NetBSD/misc/pooka/rump.js/
netBSD -> browser -> jsBSD -> browser -> jsBSD ->
I found a project that emulates an x86 processor, and they already have two BSD images built. https://copy.sh/v86/
NetBSD-9 was just released; grab appropriate install img[0] and dive in!
When you need help or community, #netbsd on freenode[1] is just a few keystrokes away.
[0] http://ftp.netbsd.org/pub/NetBSD/NetBSD-9.0/
[1] irc.freenode.org w your favourite IRC client
One does not need a NetBSD host. This is not the most time/space efficient method I can think of, but it's the easiest to explain...
On Linux host:
1. Download
for x in gnusrc sharesrc syssrc src;do ftp ftp://ftp.netbsd.org/pub/NetBSD/NetBSD-9.0/source/sets/$x.tgz&& tar xzf $x -C /;done
2. Compile toolchain mkdir /usr/obj
PATH=/bin:/sbin:/usr/bin:/usr/sbin ./build.sh -m i386 tools
3. Make filesystemUsing makefs instead of vnconfig + mount + newfs has the advantage that makefs is part of the toolchain while vnconfig is not
makefs root.img fakecrackerI experimented with something like that with Linux and cloud-hypervisor (a firecracker fork): https://gist.github.com/gdamjan/1f260b58eb9fb1ba62d223495858...
> In November 2018 AWS published an Open Source tool called Firecracker, ...
Aha. Reading now.
Chroot vulnerabilities have been discovered and fixed over time, as any security issue in an operating system is. It's not accurate to say that they are insecure in a blanket fashion especially these days. My opinion is that we should be using Unix as it is meant to be used, as on operating system, and using its time worn facilities meant for purposes such as security and sandboxing. They are very well tested and the solutions are baked-in and generally pretty small in terms of both code and overhead when compared to spinning up a VM, for instance. There are arguments for using VMs for security and scaling but they don't always win over just one modest local server in either domain. We're not all serving Google search after all.
I think you are right in general terms but I do not think an attacker will play by the rule and use `chroot` in UNIX-like OS as it is "meant to be used". They will use whatever means necessary - whether it be 0day or other un-patched vulnerability to get a break out.
If you are implying _PoC GTFO_, then definitely I do not have anything to suggest today that either is secure but I would rather not base my comment on what's not seen in the wild and also on the limited breadth of my research.
If anything, we've learnt the from past exploitations of guest additions/kernel modules in guests/vmm, that all of it is real and possible. Given enough resource, time and eyeballs, a _lot_ of the bugs are exploitable - you just have to ask some of the folks in offsec who develop exploits for living.