Jailed/sandboxed/chrooted applications

Fabian Keil freebsd-listen at fabiankeil.de
Fri Jan 2 13:00:37 UTC 2009


Adlesshaven <adlesshaven at embarqmail.com> wrote:

> Does anyone here jail, sandbox or chroot the applications they use with Tor?

I'm running Tor and Privoxy in FreeBSD jails,
Xorg applications (which probably pose a bigger thread)
are running on the host system, though.

> I have been trying to adapt the Wiki's transparent proxy recommendations
> to a FreeBSD jail for the last couple weeks with no luck.

I wrote about trans-proxy-tor running in a FreeBSD jail at:
http://www.fabiankeil.de/blog-surrogat/2006/06/15/jail-experimente-mit-ezjail.html

The text is in German but the only thing that really matters is
the /etc/devfs.rules example to make /dev/pf visible in the jail.

Nowadays I use Tor's TransPort option instead of trans-proxy-tor,
but the configuration is pretty much the same.

Fabian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20090102/890a9d9a/attachment.pgp>


More information about the tor-talk mailing list