|
|
|
|
|
by Zurrrrr
1202 days ago
|
|
> They aren’t (and do not) require any privleged system calls, whatsoever. You're making a distinction about 'privileged' system calls, why, exactly? You really think something like Oracle won't require access to a ton of syscalls to work correctly? > If you can actually exploit a system call, neither a MAC based approach or a pledge will help. MAC will, pledge won't. For example with SELinux:https://www.kernel.org/doc/Documentation/prctl/seccomp_filte... |
|