Сайт Роскомнадзора атаковали18:00
Copyright © ITmedia, Inc. All Rights Reserved.
。关于这个话题,heLLoword翻译官方下载提供了深入分析
Артем Соколов (Редактор отдела «Силовые структуры»)
Container egress filtering uses nftables rules inside the container. A root process with cap_net_admin could bypass these rules. The pixel user has restricted sudo that only permits safe-apt, dpkg-query, systemctl, journalctl, and nft list.
Two people involved in the contamination were executed.