Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Hiding Payloads in Linux Extended File Attributes, (Thu, Jul 17th)

published on 2025-07-17 06:54:56 UTC by
Content:
This week, it's SANSFIRE[1]! I'm attending the FOR577[2] training ("Linux Incident Response & Threat Hunting"). On day 2, we covered the different filesystems and how data is organized on disk. In the Linux ecosystem, most filesystems (ext3, ext4, xfs, ...) support "extended file attributes", also called "xattr". It's a file system feature that enables users to add metadata to files. These data is not directly made available to the user and may contain anything related to the file (ex: the author's name, a brief description, ...). You may roughly compare this feature to the Alternate Data Stream (ADS) available in the Windows NTFS filesystem.
Article: Hiding Payloads in Linux Extended File Attributes, (Thu, Jul 17th) - published 3 months ago.

https://isc.sans.edu/diary/rss/32116   
Published: 2025 07 17 06:54:56
Received: 2025 07 17 07:14:53
Feed: SANS Internet Storm Center, InfoCON: green
Source: SANS Internet Storm Center, InfoCON: green
Category: Alerts
Topic: Vulnerabilities
Views: 13

Custom HTML Block

Click to Open Code Editor