Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

you are viewing a single comment's thread
view the rest of the comments
[–] 0 points 2 years ago (1 child)

Instead of giving it a LLVM based shell, can you give it an actual shell in a container? Maybe backed by AppArmor or SELinux to prevent breakouts

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago

    Tempting, but in order to reduce the potential attack surface, I'm likely just to create a simple simulator instead now.

    If it's good enough to fool the first few interactions of an automated script, that'll probably do. That'll give me the curl/wget target they're trying to insect me with, most likely.

    It means I can potentially create a single binary docker instance that can be reset practically instantly by deleting/reimporting.

  • source
  • parent