Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

mushu@social.troll.academyM

mushu@social.troll.academy

@mushu@social.troll.academy
Über
Beiträge
9
Themen
1
Shares
0
Gruppen
0
Follower
0
Folge ich
0

View Original

Beiträge

Aktuell Bestbewertet Umstritten

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @uint8_t might've been this: https://social.troll.academy/@mushu/115941118741449240

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    Thanks to @cxiao for highlighting these:

    https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
    https://opensourcemalware.com/blog/contagious-interview-vscode

    .. I do know that the version of tokenlinux.sh I retrieved also downloads node and executes something with it.

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @zedaardv outch - sorry to hear that 🫤

    I mean there are some cases where device surveillance makes sense from a compliance perspective, but it should never be a surprise and be clearly documented upfront.

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @freya thanks 💖
    If fedi is any measure there are amazing, kind people out there. Some of them even do software.

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @sol_hsa yeah - I also think it's bigger than a single editor. Jetbrains does it too: https://www.jetbrains.com/help/idea/project-security.html

    Not even starting to think about editors that are more 'AI enabled' ^^

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @codecat yeah, that's sad indeed.

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @temptoetiam hey 🙂
    yes - I was lucky to detect foul play and happened to be careful.

    I found that software would've run that loaded and executed other software. From what I could see the setup in the end was one where my machine would've executed whatever the attackers wanted with user privileges.

    I'm not 100% sure what the endgame would've been. Could've gone for ransomware, information stealing, botnets you name it.

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    @morl99 yes, I agree it could be more explicit. That'd also aid with the step of attackers trying to obfuscate the code execution by adding whitespace in the json.

    Uncategorized

  • Sometimes the job interview just wants to gain code exec on your machine:
    mushu@social.troll.academyM mushu@social.troll.academy

    Sometimes the job interview just wants to gain code exec on your machine:

    https://runjak.codes/posts/2026-01-21-adversarial-coding-test/

    Local girl failed the coding interview:
    I don't think they've got a job for me anymore now that I got their repos deleted⁉️

    Uncategorized
  • Anmelden

  • Du hast noch kein Konto? Registrieren

  • Anmelden oder registrieren, um zu suchen
  • Erster Beitrag
    Letzter Beitrag
0
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum