Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Echo the LD_PRELOAD environment variable first and check for anything suspect.


Unless the shared object file also includes an override for the function that expands environment variables to lie about the true value of LD_PRELOAD.


the twist: echo is also hijacked...


Okay... just type "Export" then.


okay, so now the getenv call is hijacked too. You can play this game all day, as long as the environment is stored in user space, you can get it and fake the output.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: