Compare commits

...
2 changed files with 8 additions and 0 deletions
+7
View File
@@ -115,6 +115,9 @@ static const std::unordered_map<std::string, AuditEventCategory> audit_event_cat
{"subprocess.Popen", AuditEventCategory::ProcessCreate},
{"_winapi.CreateProcess", AuditEventCategory::ProcessCreate},
{"_posixsubprocess.fork_exec", AuditEventCategory::ProcessCreate},
// processreplace: exec* replaces the current process image rather than spawning a child
{"os.exec", AuditEventCategory::ProcessReplace},
};
// Returns the category event_name belongs to, or AuditEventCategory::None when it isn't audited.
@@ -708,6 +711,7 @@ static const std::unordered_map<std::string, std::vector<Py_ssize_t>> audit_targ
{"pty.spawn", {0}},
{"_winapi.CreateProcess", {1, 0}},
{"_posixsubprocess.fork_exec", {0}},
{"os.exec", {0}},
};
AuditEventCategory open_category(PyObject* args)
@@ -761,6 +765,7 @@ std::vector<std::string>* permission_list_for(AuditEventCategory category, Plugi
case AuditEventCategory::Http: return &permissions.network_http;
case AuditEventCategory::Socket: return &permissions.network_socket;
case AuditEventCategory::ProcessCreate: return &permissions.process;
case AuditEventCategory::ProcessReplace: return &permissions.process;
default: return nullptr;
}
}
@@ -832,6 +837,8 @@ wxString audit_message(AuditEventCategory category, const wxString& plugin_name,
return wxString::Format(_L("Plugin \"%s\" is requesting to open a network connection to:\n%s"), plugin_name, target_list);
case AuditEventCategory::ProcessCreate:
return wxString::Format(_L("Plugin \"%s\" is requesting to run the following command(s):\n%s"), plugin_name, target_list);
case AuditEventCategory::ProcessReplace:
return wxString::Format(_L("Plugin \"%s\" is requesting to replace the running application with:\n%s"), plugin_name, target_list);
default:
return wxString::Format(_L("Plugin \"%s\" is requesting permission for the Python audit event \"%s\"."), plugin_name, event_name);
}
+1
View File
@@ -45,6 +45,7 @@ enum class AuditEventCategory {
Http,
Socket,
ProcessCreate,
ProcessReplace,
Threading,
};