Skip to content

Ftype issue #298

@Thomasw2802

Description

@Thomasw2802

Hello,

I want to talk about a issue I encountered while using fapolicyd.

I tried to make rules using ftype option but I found out that it's very easy to manipulate a file ftype.
For instance, if I have a python file and I write on my first line #!/bin/bash, the ftype detected will be text/x-shellscript.
So, if I have a rule that deny python ftype it will be easy for an attacker to bypass it.
exploit_photo
image

Is it safe to use this option ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions