• mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    9 hours ago

    I forgot but do browsers download binaries as executable?

    One of the big issues with windows is the fact that it uses file extensions for determining file type, so EXEs can just be instantly run after downloading, which led to MSFT making the “Mark Of Th Web” attribute, which moved hackers into finding every type of bypass for MOTW.

    I think straight bin downloads require you to chmod +x first, but you could also probably bypass it with any archive format like .tar.gz or opting for a .deb or .rpm.

    The upside is that you really shouldn’t be downloading raw bins outside of the package manager, but there are a bunch of tools that only ship as appimages, so you’re kinda screwed if you download and execute from an untrusted source.

    • Retail4068@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      8 hours ago

      You can kindly fuck off with this level of hand holding lol. Forcing me to +x by default is a massive pain in the ass.

      • 0x0@infosec.pub
        link
        fedilink
        arrow-up
        10
        ·
        edit-2
        7 hours ago

        Forcing you to +x is the opposite of handholding. Do you want sudo to wipe your ass as well?

      • TimeSquirrel@kbin.melroy.org
        link
        fedilink
        arrow-up
        4
        ·
        7 hours ago

        You are not the only thing capable of running binaries on your system. There’s always the possibility of something else being compromised that now has the capability to run this binary.

        Security comes in many layers on top of each other and with software having to work together to plug all possible holes, not just the direct exploitation paths you are currently actively conscious about and using.