Android SELinux Internals Part IV Policy Analysis, Kernel Mi... - #2853
Open
carlospolop wants to merge 1 commit into
Open
carlospolop wants to merge 1 commit into
carlospolop wants to merge 1 commit into
Conversation
Collaborator
Author
🔗 Additional ContextOriginal Blog Post: https://8ksec.io/android-selinux-internals-part-iv Content Categories: Based on the analysis, this content was categorized under "Mobile Pentesting > Android Applications Pentesting > Android SELinux Policy Analysis and Kernel-Level Bypass". Repository Maintenance:
Review Notes:
Bot Version: HackTricks News Bot v1.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 Automated Content Update
This PR was automatically generated by the HackTricks News Bot based on a technical blog post.
📝 Source Information
🎯 Content Summary
Scope and security impact
This post explains how to audit the SELinux policy actually enforced by an Android device, identify dangerous OEM/vendor permissions, and assess the mitigations that an exploit must defeat before performing a kernel-level SELinux bypass. It does not disclose a new CVE or provide a standalone exploit. Its offensive value lies in mapping reachable files, device nodes, IPC endpoints, capabilities, and domains, then identifying permissions that can turn code exec...
🔧 Technical Details
Audit the live merged policy rather than source fragments: Run setools-android as root against
/sys/fs/selinux/policy. Query an attacker-controlled source domain withsesearch -A -s <domain>, then filter byfile,chr_file,process, Binder, Unix sockets, and transition permissions. This reveals the exact policy enforced after platform, compatibility, vendor, ODM, and injected rules have been merged.Turn SELinux rules into an attack-path graph: Begin with the initial domain and identify reachable files, character devices, Binder services, Unix sockets, and process domains. For every reachable service or HAL, inspect its own permissions for driver IOCTL access, sensitive files, executable writable locations, or capabilities such as
sys_admin,sys_rawio,sys_ptrace, andsys_mod...🤖 Agent ActionsImplemented the HackTricks update.
Changes
android-selinux-policy-analysis.mdcovering:seinfo/sesearchauditing workflowneverallowsrc/mobile-pentesting/android-app-pentesting/README.mdsrc/SUMMARY.mdValidation passed for formatting, references, code fences, forbidden sources, and
git diff --check.mdbookwas unavailable locally.This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.