End goal
End goal
Posted Jul 5, 2024 5:51 UTC (Fri) by comex (subscriber, #71521)In reply to: End goal by NYKevin
Parent article: Another try for getrandom() in the vDSO
As for why the VM forks in the first place, well, as one possibility, it could be a desktop VM which the user manually chose to fork (while some service was talking to the network in the background). Some desktop VM software offers cloning as an option. Or even without cloning, the risks seem similar if the VM is just restored from a snapshot.
Admittedly, waiting for a desktop VM to be forked/restored seems like a pretty niche thing for an attacker to do, but not completely unrealistic. I'm sure there are people who make a habit of regularly restoring their VMs from snapshot.
Posted Jul 5, 2024 20:28 UTC (Fri)
by NYKevin (subscriber, #129325)
[Link] (3 responses)
That would require the application to be originally deployed in a broken state where it randomly drops TCP connections for no apparent reason. Maybe there are some people who do that, but I wouldn't want to work there.
Posted Jul 5, 2024 20:43 UTC (Fri)
by comex (subscriber, #71521)
[Link] (2 responses)
Posted Jul 5, 2024 23:28 UTC (Fri)
by NYKevin (subscriber, #129325)
[Link] (1 responses)
Posted Jul 5, 2024 23:31 UTC (Fri)
by NYKevin (subscriber, #129325)
[Link]
End goal
End goal
End goal
End goal