3 ms·
I actually started working on a tool like that for fun, at each syscall it would walk back up the stack and check which shared object a function was from and co
by zavec 1y ago
I actually started working on a tool like that for fun, at each syscall it would walk back up the stack and check which shared object a function was from and compare that to a policy until it found something explicitly allowed or denied. I don't think it would necessarily be bulletproof enough to trust fully but it was fun to write.