Conversation
|
Bruh… fexecve isn’t a syscall? Then what exactly do you expect auditd to monitor—your hopes and dreams? |
|
Kiddo, you don't even know what a syscall is. Be happy you copied from me — you didn't even bother changing the repo name: https://github.com/vahidmalekk/bypass-Neo23x0-auditd-config |
|
The PoC I wrote clearly uses the fexecve wrapper, which is a system call, not a syscall in the literal sense. I actually saw your GitHub today for the first time — I don’t think I’ve come across your work before. Do you seriously think I’d be so naive as to copy something and leave the exact same repo name? |
|
be happy about your findings, but auditd won’t work the way you expect it to(You should read more about how auditd actually works before making pushing changes like this) It can’t monitor wrappers or what ever you call it. If you review what you pushed, you’ll notice it doesn’t work and some one else even pushed it in past https://github.com/Neo23x0/auditd/pull/156/files. |

check this PoC => https://github.com/CheraghiMilad/bypass-Neo23x0-auditd-config.git