EPISODE · Jun 26, 2026 · 27 MIN
Setting NoNewPrivs system wide as default (osc26)
from Chaos Computer Club - recent events feed (high quality) · host Thorsten Kukuk
Setuid binaries are not dangerous in themselves, but a rather worthwhile target that can lead to privilege escalation if they have a vulnerability. The goal is therefore to eliminate this attack surface. The kernel provides a solution with the no_new_privs flag, which effectively disables setuid/setgid bits and file capabilities. This flag can be set with systemd and the NoNewPrivs option in Pid1. In this talk I will present how this can be reached, what the current status is and where are the remaining problems are. about this event: https://c3voc.de
Embed this episode
Ready to play
Setting NoNewPrivs system wide as default (osc26)
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.