| ▲ | Wicher 3 days ago | ||||||||||||||||||||||||||||
I couldn't find the technique used above the fold (or a short way below). Is this something more (and something more interesting) than just standard spawned process inheriting the parent process environment? IOW is this actually injecting in the true sense of the word? Because that'd be interesting. | |||||||||||||||||||||||||||||
| ▲ | zemo 3 days ago | parent [-] | ||||||||||||||||||||||||||||
Reads like it’s not copying the parent, it’s manually constructing the env dictionary to be passed to execve explicitly. I do this in one of my tools at work because developers were exfiltrating secrets and hand jamming them into .env files. | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||