KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
So I was thinking of writing online c# compiler and execution environment. And of course problem #1 is security. I ended up creating a little-privileged appdomain for user code and starting it in a new process which is tightly monitored for cpu and memory consumption. Standard console application namespaces are available. So my question is this: can you think of ways of breaking something in some way? You can try your ideas on the spot rundotnet . Edit2 If anyone cares about the code, there is now open source fork of this project: rextester at github Edit1 As a response to one of the comments here are some code samples. So basically you create a console application. I'll just post a big chunk of it: class Sandboxer : MarshalByRefObject { private static object[] parameters = { new string[] { "parameter for the curious" } }; static void Main(string[] args) { Console.OutputEncoding = Encoding.UTF8; string pathToUntrusted = args[0].Replace("|_|", " "); string untrustedAssembly = args[1]; string entryPointString = args[2]; string[] parts = entryPointString.Split(new string[] { "|" }, StringSplitOptions.RemoveEmptyEntries); string name_space = parts[0]; string class_name = parts[1]; string method_name = parts[2]; //Setting the AppDomainSetup. It is very important to set the ApplicationBase to a folder //other than the one in which the sandboxer resides. AppDomainSetup adSetup = new AppDomainSetup(); adSetup.ApplicationBase = Path.GetFullPath(pathToUntrusted); //Setting the permissions for the AppDomain. We give the permission to execute and to //read/discover the location where the untrusted code is loaded. PermissionSet permSet = new P
Tags (comma-separated)
Save Edits
Cancel