3 ms·
Can it? If my application invokes syscalls directly, that wouldn't hit anything interposed using LD_PRELOAD.
by maffydub 6y ago
Can it?
If my application invokes syscalls directly, that wouldn't hit anything interposed using LD_PRELOAD.
- ddtaylor 6y agoIt will certainly work for the vast majority that are using #include <stdio.h> and more importantly for the various GUI apps that are using GTK/Qt dialogs.
- maffydub 6y agoThis is for security, though - you can't just assume it's good enough because it will work for most benign applications - you need to be sure it will work for all applications - benign or malicious! There are other solutions such as seccomp (as siblings of your post have pointed out) that solve this securely, but LD_PRELOAD won't.
- cycloptic 6y agoThe safest way to do it would be to implement it with seccomp so you unconditionally block those syscalls.
- acka 6y agoFirejail[1] is IMO a good alternative. It handles sandboxing using Linux namespaces and seccomp-bpf. [1] https://firejail.wordpress.com/ https://firejail.wordpress.com/