Bypass SELinux mipimo ine chekuita nekurodha kernel modules

Iko mukana wekupfuura kurambidzwa kwekurodha kernel modules, inoshandiswa mune yakanangwa SELinux mitemo pane imwe yemidziyo yakadzidzwa, yakaratidzwa (hazvina kutaurwa kuti ndeipi mudziyo uye kuti dambudziko rinokanganisa sei mitemo yeSELinux mune firmware uye kugovera). Kuvhara mamodules mumitemo yeSELinux inosanganisirwa yaive yakavakirwa pakudzora kupinda kune finit_module system call, iyo inobvumidza iwe kurodha module kubva mufaira uye inoshandiswa mune zvinoshandiswa senge insmod. Nekudaro, iyo SELinux mitemo haina kufunga iyo init_module system call, iyo inogona zvakare kushandiswa kurodha kernel modules zvakananga kubva kune buffer mundangariro.

Kuti uratidze nzira, prototype yekushandisa yakagadzirirwa iyo inokutendera kuti uite kodhi padanho re kernel nekurodha module yako uye kudzima zvachose SELinux kudzivirira, kana iwe uine midzi yekuwana iyo system inogumira uchishandisa SELinux.

Source: opennet.ru

Voeg