Hacker News (curated)new | past | comments | ask | show | jobs| show hidden

The attacker could use `chattr -i .bashrc` with the same privileges before editing your bashrc. A better way would probably be to use `sudo chown 0:0 .bashrc`.

Also you will want to do the same to .profile (because of LD_PRELOAD etc). And also do the same to any directories in your $PATH (~/.local/bin etc)





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact | github