Hiding Payloads in Linux Extended File Attributes, (Thu, Jul 17th)
ID: e2e6fe84-4984-53af-ad41-a977ea2ba7f0
STIX ID: report--e2e6fe84-4984-53af-ad41-a977ea2ba7f0
Feed Name: SANS ISC Diary
This report illustrates a proof-of-concept for hiding a Python reverse-shell payload in Linux extended file attributes (xattr), splitting it across multiple files, obfuscating with XOR and Base64, and later reconstructing it with a C tool; it concludes with a simple defensive tip to hunt such misuse by recursively listing xattrs using `getfattr -R`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
