Elektrine lite

← Feed

@barubary@infosec.exchange

2026-09-19 00:27 UTC

I don't know who needs to hear this, but: A Linux process can voluntarily restrict the files it (and any children it spawns) may access (and how) using the landlock(7) API. Also, prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) prevents a process from gaining privileges by executing a setuid program. This seems like a great way to lock down worker processes that parse untrusted user input. If set up correctly, even if an attacker manages to take over, the attacker is limited in what they can do because they might not be allowed to write or execute any files, for example. #linux #landlock

Replies (0)

No replies.