Sign inSign up

disconnect3d/nsjail

By disconnect3d

•Updated over 4 years ago

Unofficial nsjail docker image built upon official nsjail Dockerfile.

Image
1

4.9K

disconnect3d/nsjail repository overview

Ping me somewhere if you want me to update it (e.g. disconnect3d on freenode irc).

This is a Nsjail docker image built upon https://github.com/google/nsjail/blob/master/Dockerfile⁠

The tags corresponds to git tags or commit ids. Currently, the latest version points to the git comit 7de87ae (NOTE: aka the 3.0 tag/branch).

Nsjail - description taken from github:

A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) http://nsjail.com⁠


Example Dockerfile for hosting a CTF task:

FROM disconnect3d/nsjail

RUN apt-get update && apt-get install -y \
    gcc g++

MKDIR /task
WORKDIR /task
ADD . /task
RUN g++ task_code.cpp -o task_exec && rm task_code.cpp

Then you can launch your container e.g. with such command:

docker run --privileged <yourimage> nsjail -Ml --port 3001 --user 99999 --group 99999 --disable_proc --chroot /task --time_limit 15 -R /lib/ -R /lib64/ -R /usr/bin/ /task_exec

Tag summary

Content type

Image

Digest

Size

133.2 MB

Last updated

almost 7 years ago

docker pull disconnect3d/nsjail