Nmap Development mailing list archives

Sandboxing Techniques for Nmap in the Cloud


From: Patrick Donnelly <batrick () batbytes com>
Date: Tue, 4 May 2010 00:08:48 -0400

This is part of Alexandru's Cloud GSoC project [1]. I wondered what
everyone's thoughts were on sandboxing Nmap? I figure this has
particular importance with respect to NSE and misbehaving scripts. A
current evolving practice in distributed computing research is to
setup virtual machines dynamically that can do work. My feeling is
that we could setup something similar that launches VMs so Nmap can
run with root access while not being able to compromise the host. I
envision it using a distributed VM creator like Eucalyptus to
accomplish this.

[1] http://seclists.org/nmap-dev/2010/q2/350

-- 
- Patrick Donnelly
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: