logoalt Hacker News

otterleylast Sunday at 7:58 PM3 repliesview on HN

Typical defense against this is to mount all user-writable filesystems as `noexec` but unfortunately most OSes don't do that out of the box.


Replies

mr_mitmlast Sunday at 8:05 PM

It could have created a bash alias then. And I don't think a dev wants to be restricted in creating executables. Again, if a dev can do it, so can the malware.

dividuumlast Sunday at 9:46 PM

I remember you could trivially circumvent that with „/lib/ld-linux.so <executable>“. Does that no longer work?

show 1 reply
LtWorflast Sunday at 11:58 PM

Kinda hard to work as a software developer then.