Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent Overwrite of Santa Databases #569

Merged
merged 4 commits into from
Aug 12, 2021
Merged

Prevent Overwrite of Santa Databases #569

merged 4 commits into from
Aug 12, 2021

Conversation

tnek
Copy link
Contributor

@tnek tnek commented Aug 12, 2021

SNTEndpointSecurityManager checks the source of an es_event_rename_t for tampering with the santa databases (events.db and rules.db) but it doesn't check destinations. A user can arbitrarily overwrite either Santa database by renaming a file into the databases to remove/modify rules and events.

@google-cla google-cla bot added the cla: yes label Aug 12, 2021
@tnek tnek requested a review from pmarkowsky August 12, 2021 13:45
@tnek tnek merged commit 9923f60 into google:main Aug 12, 2021
@tnek tnek deleted the bypassfix branch August 12, 2021 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants