Hacker News new | ask | show | jobs
by tptacek 1117 days ago
This isn't a bypass of "eBPF", so much as it is a bypass of a detection system that watches only the write(2) system call, and not writev(2), sendfile(2), or io_uring.