December 2018
Beginner
826 pages
22h 54m
English
While AppArmor is nice and it definitely does what it advertises, there are some caveats:
It also goes off path, rather than inode, meaning you can do things such as create a hardlink to bypass restrictions:
$ sudo ln /usr/sbin/tcpdump /usr/sbin/tcpdump-clone
Admittedly, if you're on a box and have sudo, it's pretty much game over at that point anyway:
$ sudo tcpdump -i enp0s3tcpdump: enp0s3: You don't ...