Hacker News new | ask | show | jobs
by Wowfunhappy 1962 days ago
> Directories listed in multiple users' $PATH that are writable without superuser privileges can be used for attacks (e.g., by placing a sudo binary that will log the password there). The same can be done by malicious software running as your user in order to get your password

Yikes. That particular attack did not occur to me.