Ich kann Deutsch erst am Niveau B2 sprechen.

  • 3 Posts
  • 935 Comments
Joined 1 year ago
cake
Cake day: June 6th, 2023

help-circle











  • Yeah, (O)OP is such a rookie they probably call it Homework, which is a well-known trick. The correct stealth strategy is a directory called linux_malware_test_vm_imgs containing archives such as

    clamav_analysis_cumulative.tar
    CVE-2022-4907_ffmpeg_backdoor.tar
    CVE-2024-3094_xz_backdoor.tar
    CVE-2024–2961_php_24yo_chinese_string_insertion.tar
    gimp_2022-11-01_trojan.tar
    löve2d_hump_bundle.tar
    löve2d_pölygamy_crash.tar
    löve2d_yaoui.tar
    malwarebytes_tarball_anal.tar
    qt_vuln_sql_6.3.0.tar
    tcp_heading_segment_length_handling_overflow.tar
    

  • I know PDF providers who visibly print the customer’s name or number in the header of every page, along with short copyright text. I use qpdf --stream-decompress to make the PDF into human-readable PostScript, and then Python+regex to remove each header text, which stand out a bit from other PDF elements. The script throws an error if more or fewer elements than pages have been removed but that hasn’t happened yet. Processed documents sometimes have screwed-up non-ASCII characters in the Table of Contents for some reason but I don’t have the originas anymore so IDK if it’s my fault. Still, I wouldn’t share the PDFs unless in text-only or printed form because of any other steganographic shenanigans in the file. I would absolutely torrent them if I could repurchase them under a new identity and verify that the files are identical.

    BTW, has anyone figured out how to embed Python code in PDF? The whitespace always gets reencoded as x-coordinates so copy&pasting it never preserves indentation. No, you can’t use the Ogham Space Mark (Unicode’s only non-blank character classified as a space) for indentation in Python, I tried.