Loading posts...
  • User namespace and kernel capability

    A lot of kernel reachable code is only available from an already-privileged user. To restrict features for unprivileged user, the kernel generally uses capabilities. Ubuntu enabled unprivileged user namespace by default, which gives kernel exploit more attack surface. Nowadays most kernel modules are guarded by different capabilities, such as CAP_NET_ADMIN, CAP_NET_RAW. To trigger a vulnerability that…

  • 二十四年


  • Switch Dashlane to Bitwarden

    I’ve been using Dashlane for years, it’s the best password management software I ever used, even when I made the decision that migrating all my passwords to Bitwarden, I still believe no other password management software can compete with Dashlane. So why did I abandon Dashlane anyway and embrace an ugly, incomplete, open-source password management…

  • 一个女人和另一个女人


  • 哈瓦那的夜港