Indicating events that are vulnerable to TOCTOU #1355
OriGlassman
started this conversation in
Development
Replies: 1 comment
-
Good idea. Let's create an issue for this. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Users should be aware of events that are vulnerable to time of use to time of check (TOCTOU) attacks.
I think every event in tracee-ebpf should mention whether they are vulnerable or not, instead of "forcing" the user to google the event and check whether this is a syscall, lsm hook, kernel tracepoint etc.
The event documentation should clearly state whether it's vulnerable, and the relevant vulnerable fields (arguments).
Beta Was this translation helpful? Give feedback.
All reactions