News Score: Score the News, Sort the News, Rewrite the Headlines

The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction

Recently, Ubuntu introduced sandbox mechanisms to reduce the attack surface, and they seemed unbreakable. However, after carrying out in-depth research, we found that the implementation contained some issues, and bypassing it was not as difficult as expected. This post will explain how we began our research at the kernel level and discovered a bypass method. We will also share some interesting stories from the process. 1. Introduction 1.1. Ubuntu’s New Sandbox Model After years of serving as a r...

Read more at u1f383.github.io

© News Score  score the news, sort the news, rewrite the headlines