this post was submitted on 13 Sep 2024
50 points (98.1% liked)

Cybersecurity

5935 readers
35 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

Fake Python job opportunities used to attack programmers

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 3 points 4 months ago* (last edited 4 months ago)

I'm assuming they just send you a zip file with an 'existing codebase' where somewhere in a hidden dependency a bit of code does something nefarious when you first run the project. You don't even need root access to do something bad, your whole home directory is interesting enough as it is (emails, SSH keys, saved browser passwords, etc).

Not everyone is going to do a coding test in a separate account or in a VM.