149 karma · joined August 20, 2017
> securelevel may no longer be lowered except by init
> The list of securelevel's effects may not be comprehensive.
So yes, it's a nice sandbox that can help prevent accidents, but doesn't sound like something you should rely on for actual defense.
That's generally called pivoting and has nothing to do with method of persistence of the malicious code.
OP makes a point that certain systems move or have moved away from giving root user the ability to extend/modify kernel code at runtime via kernel modules, my argument is that none of that matters since root user can still extend/modify kernel code at runtime via binary patching.
#include <stdio.h>
#include <stdlib.h>
static void begin() __attribute__((constructor));
void begin() {
unsetenv("LD_PRELOAD");
}
Build with: gcc -shared -fpie -o library.so library.c
Test: LD_PRELOAD=~/library.so env | grep LD_PRELOAD2. I'd suggest against using `strings` (let alone with sudo) on attacker controlled inputs
EU should be there to set goals, not to dictate implementation.
How does the demon attain the knowledge of what is "fast" and "slow" without continuous observation (and thus interaction) with the particles. Velocity is just function of position over time, so the demon needs at least 2 samples to make the most basic approximation. Where is the entropy for doing that coming from? How does the interference of the measuring apparatus factor into the whole process - what if the sole act of measurement changes the state of the particle from "fast" to "slow" or vice versa? Do we need to measure twice? But what if the second measurement causes the transition it was meant to detect?
all_members = ", ".join(members)
all_scores = ", ".join(map(str, scores))
print(f'{id:<5} {all_members:<50} {all_scores:<30}')https://en.wikipedia.org/wiki/List_of_most_expensive_video_g...
If there's a security issue you need to rebuild your images anyway and optimally you have a system in place that represents images and their dependencies as some sort of dependency graph structure, so when you upgrade your base image all dependent images get rebuilt automatically.
Some feedback/things I'd like to see (or not see):
- Make the Comments section collapsible, right now it takes 1/4 of the screen
- Filtering by categories is kinda confusing, since filters affect both the left sidebar as well as the main view I'd expect the filtering UI to sit on top of both
- Better visibility/categorization for parameters that can only be set via command line