Passez à l'illimité avec Magzter GOLD

Passez à l'illimité avec Magzter GOLD

Obtenez un accès illimité à plus de 9 000 magazines, journaux et articles Premium pour seulement

$149.99
 
$74.99/Année

Essayer OR - Gratuit

Horse Trick

Linux Magazine

|

#293/April 2025: Trojan Horse

Malicious Trojan horse programs have been part of the IT landscape for decades. It is easier than you think to create an application with a secret purpose. We'll show you how.

- By Andrea Ciarrocchi

Horse Trick

At the end of the legendary Trojan war, the Greeks left an offering for the people of Troy – a giant statue of a horse. Marveling at the gift, the Trojans brought the horse within their walls, not realizing it contained a lethal payload: Greek soldiers who would open the gates and let the Greek armies in to destroy the city. In other words, the Trojan horse was not what it appeared to be.

imageFigure 1: Installing Python tools in VS Code.

In today’s world, the term Trojan horse refers to a program that is not what it appears to be. A Trojan horse is a form of malware that appears to have a legitimate purpose but secretly performs some malicious function. Trojan horse programs are sometimes used to open a backdoor or harvest information for a remote attack. Some Trojan horse apps take the form of ordinary Linux utilities like ps or ls. Others might pass through links sent with email messages.

The increase in Linux’s popularity means malicious actors are also paying more attention, and the spread of harmful software will likely keep apace. Creating malware is often considered a dark art that only criminal hackers and spies truly understand, but the purpose of this article is to show just how easy it is to embed malicious code within an application. Of course, I will not provide any actual malicious code for this experiment. The sample code is just a placeholder for additional commands that an attacker could hide within the container application.

The project consists of two scripts in Python and a simple application in C++. The choice of Python arises from its portability, its ability to produce interpretable code or multi-platform executable packages, and its ease of use, which will allow me to achieve the desired result with just a handful of lines. The example listings are available for download [1].

Linux Magazine

Cette histoire est tirée de l'édition #293/April 2025: Trojan Horse de Linux Magazine.

Abonnez-vous à Magzter GOLD pour accéder à des milliers d'histoires premium sélectionnées et à plus de 9 000 magazines et journaux.

Déjà abonné ?

PLUS D'HISTOIRES DE Linux Magazine

Linux Magazine

Exercise Place

The GRUB 2 boot manager might seem intimidating at first glance. All the more reason to spin up a virtual playground so you can practice.

time to read

10 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Terminal Mosaic

What's better than one command line? Many command lines that never die. Take the terminal to new places with Zellij.

time to read

9 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

MakerSpace

Build a Long-Range Sensor Network with ChirpStack Sensor Symphony

time to read

14 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

How Flatpak, AppImage, and Snap are changing software distribution Ship It!

Modern-day package systems solve some problems posed by classic formats like DEB and RPM. We look at Flatpak, AppImage, and Snap and describe how they differ.

time to read

12 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

Dashboard Delight

Simplify the chaos of self-hosted services with Homepage, a customizable dashboard with widgets that put service statistics at your fingertips.

time to read

9 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

MADDOG'S DOGHOUSE

Free software, and the FOSS community, can help technology students get the education they desire in Brazil and elsewhere.

time to read

3 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

Rethinking the Terminal

The Warp AI agent takes the guesswork out of working at the command line. We show you how to build a simple website with one prompt.

time to read

4 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Just in Time

Just is a command runner that lets you define project-specific tasks in a declarative justfile.

time to read

7 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

The Watcher

This versatile security app checks for vulnerabilities, watches logs, and acts as a single interface for other tools.

time to read

7 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

NO INTERNETREQUIRED

This new utility lets you update a system that is notconnected to the Internet.

time to read

4 mins

#298/September 2025: Indie Game Studio

Hindi(हिंदी)
English
Malayalam(മലയാളം)
Spanish(español)
Turkish(Turk)
Tamil(தமிழ்)
Bengali(বাংলা)
Gujarati(ગુજરાતી)
Kannada(ಕನ್ನಡ)
Telugu(తెలుగు)
Marathi(मराठी)
Odia(ଓଡ଼ିଆ)
Punjabi(ਪੰਜਾਬੀ)
Spanish(español)
Afrikaans
French(français)
Portuguese(português)
Chinese - Simplified(中文)
Russian(русский)
Italian(italiano)
German(Deutsch)
Japanese(日本人)

Listen

Translate

Share

-
+

Change font size