Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. Sometimes the job interview just wants to gain code exec on your machine:

Sometimes the job interview just wants to gain code exec on your machine:

Geplant Angeheftet Gesperrt Verschoben Uncategorized
33 Beiträge 22 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • mushu@social.troll.academyM This user is from outside of this forum
    mushu@social.troll.academyM This user is from outside of this forum
    mushu@social.troll.academy
    schrieb zuletzt editiert von
    #1

    Sometimes the job interview just wants to gain code exec on your machine:

    https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

    Local girl failed the coding interview:
    I don't think they've got a job for me anymore now that I got their repos deleted⁉️

    morl99@hessen.socialM codecat@meow.socialC reynir@social.data.coopR temptoetiam@eldritch.cafeT gkrnours@mastodon.gamedev.placeG 18 Antworten Letzte Antwort
    1
    0
    • svenja@mstdn.gamesS svenja@mstdn.games shared this topic
    • mushu@social.troll.academyM mushu@social.troll.academy

      Sometimes the job interview just wants to gain code exec on your machine:

      https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

      Local girl failed the coding interview:
      I don't think they've got a job for me anymore now that I got their repos deleted⁉️

      morl99@hessen.socialM This user is from outside of this forum
      morl99@hessen.socialM This user is from outside of this forum
      morl99@hessen.social
      schrieb zuletzt editiert von
      #2

      @mushu that is crazy... thanks for posting about it.

      Is it just me, or could the dialog be a little more specific about WHAT it automatically executes? And: why do I want my IDE to automatically execute stuff in a repo I open? What is the positive use case of such a feature? (I am an IntelliJ user, so that is a genuine question)

      mushu@social.troll.academyM joshix@fosspri.deJ 2 Antworten Letzte Antwort
      0
      • mushu@social.troll.academyM mushu@social.troll.academy

        Sometimes the job interview just wants to gain code exec on your machine:

        https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

        Local girl failed the coding interview:
        I don't think they've got a job for me anymore now that I got their repos deleted⁉️

        codecat@meow.socialC This user is from outside of this forum
        codecat@meow.socialC This user is from outside of this forum
        codecat@meow.social
        schrieb zuletzt editiert von
        #3

        @mushu I hate how many inexperienced or unsuspecting devs are gonna fall for this 😞

        mushu@social.troll.academyM 1 Antwort Letzte Antwort
        0
        • morl99@hessen.socialM morl99@hessen.social

          @mushu that is crazy... thanks for posting about it.

          Is it just me, or could the dialog be a little more specific about WHAT it automatically executes? And: why do I want my IDE to automatically execute stuff in a repo I open? What is the positive use case of such a feature? (I am an IntelliJ user, so that is a genuine question)

          mushu@social.troll.academyM This user is from outside of this forum
          mushu@social.troll.academyM This user is from outside of this forum
          mushu@social.troll.academy
          schrieb zuletzt editiert von
          #4

          @morl99 yes, I agree it could be more explicit. That'd also aid with the step of attackers trying to obfuscate the code execution by adding whitespace in the json.

          1 Antwort Letzte Antwort
          0
          • mushu@social.troll.academyM mushu@social.troll.academy

            Sometimes the job interview just wants to gain code exec on your machine:

            https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

            Local girl failed the coding interview:
            I don't think they've got a job for me anymore now that I got their repos deleted⁉️

            reynir@social.data.coopR This user is from outside of this forum
            reynir@social.data.coopR This user is from outside of this forum
            reynir@social.data.coop
            schrieb zuletzt editiert von
            #5

            @mushu oh no, how rude of them! Thanks for sharing and good luck in your job search!

            1 Antwort Letzte Antwort
            0
            • mushu@social.troll.academyM mushu@social.troll.academy

              Sometimes the job interview just wants to gain code exec on your machine:

              https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

              Local girl failed the coding interview:
              I don't think they've got a job for me anymore now that I got their repos deleted⁉️

              temptoetiam@eldritch.cafeT This user is from outside of this forum
              temptoetiam@eldritch.cafeT This user is from outside of this forum
              temptoetiam@eldritch.cafe
              schrieb zuletzt editiert von
              #6

              @mushu sorry, non techie here: iiuc you detected foul play in the depository. Would it have infected your machine? Done something else?

              mushu@social.troll.academyM 1 Antwort Letzte Antwort
              0
              • temptoetiam@eldritch.cafeT temptoetiam@eldritch.cafe

                @mushu sorry, non techie here: iiuc you detected foul play in the depository. Would it have infected your machine? Done something else?

                mushu@social.troll.academyM This user is from outside of this forum
                mushu@social.troll.academyM This user is from outside of this forum
                mushu@social.troll.academy
                schrieb zuletzt editiert von
                #7

                @temptoetiam hey 🙂
                yes - I was lucky to detect foul play and happened to be careful.

                I found that software would've run that loaded and executed other software. From what I could see the setup in the end was one where my machine would've executed whatever the attackers wanted with user privileges.

                I'm not 100% sure what the endgame would've been. Could've gone for ransomware, information stealing, botnets you name it.

                temptoetiam@eldritch.cafeT 1 Antwort Letzte Antwort
                0
                • mushu@social.troll.academyM mushu@social.troll.academy

                  Sometimes the job interview just wants to gain code exec on your machine:

                  https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                  Local girl failed the coding interview:
                  I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                  gkrnours@mastodon.gamedev.placeG This user is from outside of this forum
                  gkrnours@mastodon.gamedev.placeG This user is from outside of this forum
                  gkrnours@mastodon.gamedev.place
                  schrieb zuletzt editiert von
                  #8

                  @mushu oh yes, putting a lot of whitespace at the start of a command is a classic in roblox malware

                  1 Antwort Letzte Antwort
                  0
                  • codecat@meow.socialC codecat@meow.social

                    @mushu I hate how many inexperienced or unsuspecting devs are gonna fall for this 😞

                    mushu@social.troll.academyM This user is from outside of this forum
                    mushu@social.troll.academyM This user is from outside of this forum
                    mushu@social.troll.academy
                    schrieb zuletzt editiert von
                    #9

                    @codecat yeah, that's sad indeed.

                    1 Antwort Letzte Antwort
                    0
                    • morl99@hessen.socialM morl99@hessen.social

                      @mushu that is crazy... thanks for posting about it.

                      Is it just me, or could the dialog be a little more specific about WHAT it automatically executes? And: why do I want my IDE to automatically execute stuff in a repo I open? What is the positive use case of such a feature? (I am an IntelliJ user, so that is a genuine question)

                      joshix@fosspri.deJ This user is from outside of this forum
                      joshix@fosspri.deJ This user is from outside of this forum
                      joshix@fosspri.de
                      schrieb zuletzt editiert von
                      #10

                      @mushu @morl99 I think IntelliJ also automatically executes stuff when you open a repo

                      https://www.jetbrains.com/help/idea/project-security.html

                      morl99@hessen.socialM 1 Antwort Letzte Antwort
                      0
                      • mushu@social.troll.academyM mushu@social.troll.academy

                        @temptoetiam hey 🙂
                        yes - I was lucky to detect foul play and happened to be careful.

                        I found that software would've run that loaded and executed other software. From what I could see the setup in the end was one where my machine would've executed whatever the attackers wanted with user privileges.

                        I'm not 100% sure what the endgame would've been. Could've gone for ransomware, information stealing, botnets you name it.

                        temptoetiam@eldritch.cafeT This user is from outside of this forum
                        temptoetiam@eldritch.cafeT This user is from outside of this forum
                        temptoetiam@eldritch.cafe
                        schrieb zuletzt editiert von
                        #11

                        @mushu thank you very much for your kind explanation!

                        1 Antwort Letzte Antwort
                        0
                        • mushu@social.troll.academyM mushu@social.troll.academy

                          Sometimes the job interview just wants to gain code exec on your machine:

                          https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                          Local girl failed the coding interview:
                          I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                          sol_hsa@mastodon.gamedev.placeS This user is from outside of this forum
                          sol_hsa@mastodon.gamedev.placeS This user is from outside of this forum
                          sol_hsa@mastodon.gamedev.place
                          schrieb zuletzt editiert von
                          #12

                          @mushu Chripes, that sounds like a major misfeature in vscode.

                          mushu@social.troll.academyM 1 Antwort Letzte Antwort
                          0
                          • mushu@social.troll.academyM mushu@social.troll.academy

                            Sometimes the job interview just wants to gain code exec on your machine:

                            https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                            Local girl failed the coding interview:
                            I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                            soblow@eldritch.cafeS This user is from outside of this forum
                            soblow@eldritch.cafeS This user is from outside of this forum
                            soblow@eldritch.cafe
                            schrieb zuletzt editiert von
                            #13

                            @mushu That's called dodging a bullet

                            1 Antwort Letzte Antwort
                            0
                            • sol_hsa@mastodon.gamedev.placeS sol_hsa@mastodon.gamedev.place

                              @mushu Chripes, that sounds like a major misfeature in vscode.

                              mushu@social.troll.academyM This user is from outside of this forum
                              mushu@social.troll.academyM This user is from outside of this forum
                              mushu@social.troll.academy
                              schrieb zuletzt editiert von
                              #14

                              @sol_hsa yeah - I also think it's bigger than a single editor. Jetbrains does it too: https://www.jetbrains.com/help/idea/project-security.html

                              Not even starting to think about editors that are more 'AI enabled' ^^

                              1 Antwort Letzte Antwort
                              0
                              • mushu@social.troll.academyM mushu@social.troll.academy

                                Sometimes the job interview just wants to gain code exec on your machine:

                                https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                                Local girl failed the coding interview:
                                I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                                fischkind@chaos.socialF This user is from outside of this forum
                                fischkind@chaos.socialF This user is from outside of this forum
                                fischkind@chaos.social
                                schrieb zuletzt editiert von
                                #15

                                @mushu Maybe the real coding challenge was getting their repos deleted and now they'll offer you a job as their head of cyber security? 🤔

                                1 Antwort Letzte Antwort
                                0
                                • mushu@social.troll.academyM mushu@social.troll.academy

                                  Sometimes the job interview just wants to gain code exec on your machine:

                                  https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                                  Local girl failed the coding interview:
                                  I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                                  freya@raru.reF This user is from outside of this forum
                                  freya@raru.reF This user is from outside of this forum
                                  freya@raru.re
                                  schrieb zuletzt editiert von
                                  #16

                                  @mushu I hope you find less adversarial prospective employers!

                                  mushu@social.troll.academyM 1 Antwort Letzte Antwort
                                  0
                                  • mushu@social.troll.academyM mushu@social.troll.academy

                                    Sometimes the job interview just wants to gain code exec on your machine:

                                    https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                                    Local girl failed the coding interview:
                                    I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                                    cppguy@infosec.spaceC This user is from outside of this forum
                                    cppguy@infosec.spaceC This user is from outside of this forum
                                    cppguy@infosec.space
                                    schrieb zuletzt editiert von
                                    #17

                                    @mushu

                                    Something I still don't understand (and didn't understand when I saw @0xabad1dea 's original post): why would crims target out-of-work developers, who are more tech-savvy than most people, probably don't have much money just now, and don't have access to company codebases?

                                    0xabad1dea@infosec.exchange0 stepan@f.czS 2 Antworten Letzte Antwort
                                    0
                                    • cppguy@infosec.spaceC cppguy@infosec.space

                                      @mushu

                                      Something I still don't understand (and didn't understand when I saw @0xabad1dea 's original post): why would crims target out-of-work developers, who are more tech-savvy than most people, probably don't have much money just now, and don't have access to company codebases?

                                      0xabad1dea@infosec.exchange0 This user is from outside of this forum
                                      0xabad1dea@infosec.exchange0 This user is from outside of this forum
                                      0xabad1dea@infosec.exchange
                                      schrieb zuletzt editiert von
                                      #18

                                      @CppGuy @mushu most people applying to non-entry-level programming jobs are not out of work, the industry is notorious for requiring job hopping every two years as the only way to get a raise...

                                      additionally, many of these fake job openings are specifically in cryptocoins/gambling/etc and people applying to them are more likely to have random wallet keys lying around.

                                      1 Antwort Letzte Antwort
                                      0
                                      • freya@raru.reF freya@raru.re

                                        @mushu I hope you find less adversarial prospective employers!

                                        mushu@social.troll.academyM This user is from outside of this forum
                                        mushu@social.troll.academyM This user is from outside of this forum
                                        mushu@social.troll.academy
                                        schrieb zuletzt editiert von
                                        #19

                                        @freya thanks 💖
                                        If fedi is any measure there are amazing, kind people out there. Some of them even do software.

                                        1 Antwort Letzte Antwort
                                        0
                                        • mushu@social.troll.academyM mushu@social.troll.academy

                                          Sometimes the job interview just wants to gain code exec on your machine:

                                          https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

                                          Local girl failed the coding interview:
                                          I don't think they've got a job for me anymore now that I got their repos deleted⁉️

                                          agitatra@berlin.socialA This user is from outside of this forum
                                          agitatra@berlin.socialA This user is from outside of this forum
                                          agitatra@berlin.social
                                          schrieb zuletzt editiert von
                                          #20

                                          @mushu Did I got it wrong or was this a: "No Backup, No Mercy"-situation? I mean who gives more than strictly limited write access to strangers?
                                          BTW: I got my first it-job as a tester by crashing their system during the interview.

                                          1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum