Re: SELinux and Reverse Shell.

Lukas Vrabec <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Organization Red Hat, Inc.
Message-ID <[email protected]>
On 9/30/20 5:57 PM, Jason Long wrote:
> Hello,
> Could SELinux protect a server from Reverse Shell attacks? When hackers access to the CMSes like WordPress then they do a Reverse Shell for access to the server. Could SELinux block it?
> 

Yes, in certain cases SELinux can block the reverse shell. For more
info, please see my demo, it's few years old but the point of attack is
reverse shell:
https://www.youtube.com/watch?v=Ysshrh4aGOs

I hope it helps.
Lukas.

> Thank you.
> _______________________________________________
> selinux mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
> 


-- 
Lukas Vrabec
SELinux Evangelist,
Senior Software Engineer, Security Technologies
Red Hat, Inc.

_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE3wrP3ArXoyYgAS7LRyAaxC8pzgYFAl90z2YACgkQRyAaxC8p
zgY8ZAf+M/PRg6BLqQXTi0ebU0JOwGfIIoZwtA1FhDI9GSkBLMJSZzXAt1dDUEi8
R64U6obmkyJfdEMssm7OdSvt1n91rjD+ol8PFiFZD07G3NBHLdGkE9c1pzJkhHh5
xxLjqwoF11W7h4glJgfDKT9ASaAgHMj2gIiGhbBV/EpNzaRkxbDU044w9Ct0O8rG
Hgf5VkV5ZAmB7bf0Fp695jQDclLEpKHJQGQKGAC9a+GBIYydCAU8iamhrAuJaNZ6
xL0KZBchpFS8cCNMqwwL2rOXYOeWfXMorHorRJGdcbyVpq27hjSMRXmpHH4CeNW6
XJKsg4I8Q3B9ENiehKQ4lQ3LYmakVA==
=rROY
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.