Message269592
>> I am puzzled as to why "use safe_exec rather than exec" isn't an option
> Because you're going to have a hard time convincing malware authors to use it.
:-) So the malicious payload is the whole python command, not just file.bin. OK, fair enough. But in that case, why hook into exec? The malware author can execute arbitrary Python so doesn't *need* exec.
As I say, though, I'm not an expert in security threats, so I'm OK with accepting that there's a hole here and the proposal plugs it. |
|
Date |
User |
Action |
Args |
2016-06-30 16:20:43 | paul.moore | set | recipients:
+ paul.moore, brett.cannon, tim.golden, zach.ware, steve.dower, Alexander Riccio |
2016-06-30 16:20:43 | paul.moore | set | messageid: <1467303643.06.0.12168461001.issue26137@psf.upfronthosting.co.za> |
2016-06-30 16:20:43 | paul.moore | link | issue26137 messages |
2016-06-30 16:20:42 | paul.moore | create | |
|