[HN Gopher] Xz/liblzma: Bash-stage Obfuscation Explained
___________________________________________________________________
Xz/liblzma: Bash-stage Obfuscation Explained
Author : ecliptik
Score : 77 points
Date : 2024-03-30 21:08 UTC (1 hours ago)
(HTM) web link (gynvael.coldwind.pl)
(TXT) w3m dump (gynvael.coldwind.pl)
| politelemon wrote:
| Thanks the simplified explanation and noisy image comparison is
| quite appreciated. It gives me a good grasp of what people mean
| by the sophistication involved.
|
| I also saw a comment on reddit mentioning that the "sandboxing"
| method was sabotaged with a dot. It's on the line just after
| "#include <sys/prctl.h>" you can see a dot all the way on the
| left.
|
| https://git.tukaani.org/?p=xz.git;a=commitdiff;h=328c52da8a2...
|
| https://old.reddit.com/r/linux/comments/1brhlur/xz_utils_bac...
| sega_sai wrote:
| Did anyone search github yet for similar head | tail tricks ? I
| doubt it was invented just for this.
___________________________________________________________________
(page generated 2024-03-30 23:00 UTC)