25 ms·
yeah, it maybe makes more sense in the context of embedded machines: where your userspace is small enough, and where you already expect that most of your binari
by eigenform 3y ago
yeah, it maybe makes more sense in the context of embedded machines: where your userspace is small enough, and where you already expect that most of your binaries arent going to change underneath your feet under normal circumstances
- _8j50 3y agoOr if you are deploying stuff at large shops with decent devops staffing, you can use ima as part if your OS build pipeline. Basically to make sure what you tested and published from dev is the only thing that can run in prod. But is it possible to code inject with ptrace or /proc/self/mem? If someone can run code, can they ROP using existing binaries only and disable IMA verification? One thing I might try would be to drop unsigned/unauthenticated versions of a distro install somewhere and chroot, if the OS allows chroot it that easy to bypass IMA? because you can mount --bind anything into the chroot environment. So is it a defense only if you are restricted as a non-root user?
- natas 3y agodoesn't have to be that fancy, you can run python (which is ima/evm signed) and run arbitrary stuff. ptrace shouldn't be allowed in prod, but yes you could memfd some code segment and exec into it... still python is easier...