Skip to content

Comment on Root access to MySQL.com sold for $3k - now serving malwareparent

Comments

The problem is, how do you both

(1) Avoid obvious detection in the compromised software?

(2) Put in something that you can actually use for exploits? You have access to many hosts, but how many different configurations are there?

The only thing I can think of is have profiles for several popular packages (e.g. wordpress), and package-specific behavior for them.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.