Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. ”The archive contains a file with a crafted filename embedding a Base64-encoded Bash command.

”The archive contains a file with a crafted filename embedding a Base64-encoded Bash command.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
5 Indlæg 3 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • kugg@infosec.exchangeK This user is from outside of this forum
    kugg@infosec.exchangeK This user is from outside of this forum
    kugg@infosec.exchange
    wrote sidst redigeret af
    #1

    ”The archive contains a file with a crafted filename embedding a Base64-encoded Bash command. This filename, when processed by common shell operations like `ls`, `find`, or `eval`, triggers automatic execution without requiring user interaction or executable permissions.” What filename results in execution on `ls`? https://blog.polyswarm.io/vshell-linux-backdoor

    troed@swecyb.comT 1 Reply Last reply
    0
    • kugg@infosec.exchangeK kugg@infosec.exchange

      ”The archive contains a file with a crafted filename embedding a Base64-encoded Bash command. This filename, when processed by common shell operations like `ls`, `find`, or `eval`, triggers automatic execution without requiring user interaction or executable permissions.” What filename results in execution on `ls`? https://blog.polyswarm.io/vshell-linux-backdoor

      troed@swecyb.comT This user is from outside of this forum
      troed@swecyb.comT This user is from outside of this forum
      troed@swecyb.com
      wrote sidst redigeret af
      #2

      @Kugg Sounds like it needs a poorly written script using it for that to happen unless I'm severely off on my "living off the land" skill set.

      kugg@infosec.exchangeK 1 Reply Last reply
      0
      • troed@swecyb.comT troed@swecyb.com

        @Kugg Sounds like it needs a poorly written script using it for that to happen unless I'm severely off on my "living off the land" skill set.

        kugg@infosec.exchangeK This user is from outside of this forum
        kugg@infosec.exchangeK This user is from outside of this forum
        kugg@infosec.exchange
        wrote sidst redigeret af
        #3

        @troed ”Malicious filename remains dormant until handled by a shell script or command.
        Simply extracting the archive does not trigger execution.
        Execution occurs only when a script or command (e.g., for f in *, echo $f, eval, printf, or logging utilities) expands or evaluates the filename.” https://www.trellix.com/blogs/research/the-silent-fileless-threat-of-vshell/

        kugg@infosec.exchangeK 1 Reply Last reply
        0
        • kugg@infosec.exchangeK kugg@infosec.exchange

          @troed ”Malicious filename remains dormant until handled by a shell script or command.
          Simply extracting the archive does not trigger execution.
          Execution occurs only when a script or command (e.g., for f in *, echo $f, eval, printf, or logging utilities) expands or evaluates the filename.” https://www.trellix.com/blogs/research/the-silent-fileless-threat-of-vshell/

          kugg@infosec.exchangeK This user is from outside of this forum
          kugg@infosec.exchangeK This user is from outside of this forum
          kugg@infosec.exchange
          wrote sidst redigeret af
          #4

          @troed Checks notes … ok ill go home and add some quotes on my shell scripts asap. I’m so old I have learnt and forgotten about this trick twice.

          reynir@social.data.coopR 1 Reply Last reply
          0
          • kugg@infosec.exchangeK kugg@infosec.exchange

            @troed Checks notes … ok ill go home and add some quotes on my shell scripts asap. I’m so old I have learnt and forgotten about this trick twice.

            reynir@social.data.coopR This user is from outside of this forum
            reynir@social.data.coopR This user is from outside of this forum
            reynir@social.data.coop
            wrote sidst redigeret af
            #5

            @Kugg @troed there are so many footguns to learn about and forget about again

            1 Reply Last reply
            0
            Svar
            • Svar som emne
            Login for at svare
            • Ældste til nyeste
            • Nyeste til ældste
            • Most Votes


            • Log ind

            • Har du ikke en konto? Tilmeld

            • Login or register to search.
            Powered by NodeBB Contributors
            Graciously hosted by data.coop
            • First post
              Last post
            0
            • Hjem
            • Seneste
            • Etiketter
            • Populære
            • Verden
            • Bruger
            • Grupper