Comment on Singularity Rootkit: SELinux bypass and netlink filter (ss/conntrack hidden)parentComments−transpute8mo> The rootkit now disables SELinux enforcing mode on-demand when the ICMP reverse shell is triggered, leaving zero audit logs.Is this independent of the Linux Security Modules policy, e.g. RHEL default policy for SE Linux?
Comments
> The rootkit now disables SELinux enforcing mode on-demand when the ICMP reverse shell is triggered, leaving zero audit logs.
Is this independent of the Linux Security Modules policy, e.g. RHEL default policy for SE Linux?