Hacker News new | past | comments | ask | show | jobs | submit login

The "malicious" code at the end of the advisory looks like nothing more than a beacon announcing it was installed?

  get current working directory
  get username
  get hostname
  concatenate the last 3 together
  obfuscate(/encrypt?) this string
  send the result as a http request to (the value of the base64 string)

# Welcome Here! :)

# just toy, no harm :)

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
