logoalt Hacker News

quantummagictoday at 10:08 AM1 replyview on HN

It's not always as easy as you imply. All the attack vectors you mentioned, require root on the host, before you can make the change or install the trojan.


Replies

delamontoday at 12:43 PM

The attack gives you ability to overwrite any cached page. So you don't need to be root to "edit" /etc/passwd.

show 1 reply