Post B5orhiustQaydZm6L2 by wren6991@types.pl
(DIR) More posts by wren6991@types.pl
(DIR) Post #B5orhieDtNGfntynMu by wren6991@types.pl
0 likes, 0 repeats
Slightly annoyed at copy.fail releasing a PoC for an exploit still not patched in Ubuntu LTS so that they can advertise their AI thing
(DIR) Post #B5orhiustQaydZm6L2 by wren6991@types.pl
0 likes, 0 repeats
Uhhhhh the kernel ignores modprobe blacklist for crypto modules. I blacklisted algif_aead and I can still pop a root shell: https://github.com/torvalds/linux/blob/e75a43c7cec459a07d91ed17de4de13ede2b7758/crypto/api.c#L301-L307
(DIR) Post #B5orhjey85SUwVKuAa by leah@blahaj.social
1 likes, 0 repeats
@wren6991 that's why the mitigation changes the install handler to /bin/false and doesn't use blacklisting?
(DIR) Post #B5orrRIRG78OsxQPdA by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@leah @wren6991 Although might be worth it to ban out algif_aead.ko* from being installed as wouldn't be surprised that not everything goes through modprobe.