Get a Pentest and security assessment of your IT network.

News

‘Less’ means more to malware authors targeting Linux users

Using the “less” Linux command to view the contents of files downloaded from the Internet is a dangerous operation that can lead to remote code execution. Google security engineer Michal Zalewski: Third-party tools that lesspipe relies on have not been designed with malicious input in mind. On many Linux distributions, including Ubuntu and CentOS, it supports many more file types including archives, images and PDF. Users can protect themselves by removing LESSOPEN and LESSCLOSE environment variables if they are set on their Linux systems.”]

Source: https://www.csoonline.com/article/2851068/less-means-more-to-malware-authors-targeting-linux-users.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months