#symlink — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #symlink, aggregated by home.social.
-
GhostApproval: как AI-ассистенты пробивают модель доверия через симлинки
Техника GhostApproval позволяет вредоносному репозиторию вынудить AI-ассистента незаметно для разработчика записать данные в чувствительные файлы вне проекта, вплоть до ~/.ssh/authorized_keys.
В результате подтверждение на изменение, которое выглядит как правка обычного файла проекта, может дать злоумышленнику постоянную возможность входа по SSH.
Атака строится на старом трюке с симлинками по CWE‑61 с вишенкой на торте в виде CWE-451. Файл вроде project_settings.json или другой конфигурации, упомянутой в README, оказывается симлинком на чувствительный путь, например ~/.ssh/authorized_keys или shell-startup файл. При выполнении инструкций вроде «настрой рабочее окружение» агент следует по симлинку и записывает, например, SSH-ключ атакующего, тогда как разработчик видит подтверждение на изменение обычного файла проекта.
-
GhostApproval: как AI-ассистенты пробивают модель доверия через симлинки
Техника GhostApproval позволяет вредоносному репозиторию вынудить AI-ассистента незаметно для разработчика записать данные в чувствительные файлы вне проекта, вплоть до ~/.ssh/authorized_keys.
В результате подтверждение на изменение, которое выглядит как правка обычного файла проекта, может дать злоумышленнику постоянную возможность входа по SSH.
Атака строится на старом трюке с симлинками по CWE‑61 с вишенкой на торте в виде CWE-451. Файл вроде project_settings.json или другой конфигурации, упомянутой в README, оказывается симлинком на чувствительный путь, например ~/.ssh/authorized_keys или shell-startup файл. При выполнении инструкций вроде «настрой рабочее окружение» агент следует по симлинку и записывает, например, SSH-ключ атакующего, тогда как разработчик видит подтверждение на изменение обычного файла проекта.
-
GhostApproval bug shows AI coding agents can be tricked by decades-old symlink attacks
https://1ban.news/ghostapproval-ai-coding-agent-symlink-vulnerability-2026/
#1ban #ghostapproval #coding #agent #symlink #tech -
@carlton @sethmlarson And does the consensus against symbolic links arise from inexperience? Windows didn't let unprivileged users create symlinks in NTFS until Windows 10 build 14972 in 2018, and even then only if developer mode is on. Instead, Windows desktop users' experience since 1995 has been with shortcuts, which operate at the shell level, not the file system level.
-
@carlton @sethmlarson And does the consensus against symbolic links arise from inexperience? Windows didn't let unprivileged users create symlinks in NTFS until Windows 10 build 14972 in 2018, and even then only if developer mode is on. Instead, Windows desktop users' experience since 1995 has been with shortcuts, which operate at the shell level, not the file system level.
-
My linuxmint system system drive was filling up. I had a large "other" drive that had little on it. I worked with claude.ai to move timeshift and symlink it to the larger drive. the claude session is recorded here:
https://claude.ai/share/18c4995a-02db-414c-b8de-d86822ec7b3d
-
Now this is an interesting #Python problem. I don't know if it's a #bug, but it's a change in behaviour that I don't see documented.
I upgraded from #Debian 12/Bookworm to 13/Trixie, so the default Python3 changed from 3.11 to 3.13. A script of mine broke, because `pathlib.Path.is_mount()` changed behaviour when the path is a symlink (at least to a directory).
i.e. I'm testing a path that is a symlink. The symlink points to a directory. That directory *is* a mountpoint. The `.is_mount()` test in 3.11 returned True, while in 3.13 it returns False.
This seems wrong to me. Most path-manipulation functions transparently treat symlinks as if they were the pointed-to object unless you pass an option/flag specifically to say you want the symlink itself.
Gonna have to dig to see what else I can find.
#pathlib #path #is_mount #stdlib #behaviour #symlink #filesystem #mountpoint #mount
-
Now this is an interesting #Python problem. I don't know if it's a #bug, but it's a change in behaviour that I don't see documented.
I upgraded from #Debian 12/Bookworm to 13/Trixie, so the default Python3 changed from 3.11 to 3.13. A script of mine broke, because `pathlib.Path.is_mount()` changed behaviour when the path is a symlink (at least to a directory).
i.e. I'm testing a path that is a symlink. The symlink points to a directory. That directory *is* a mountpoint. The `.is_mount()` test in 3.11 returned True, while in 3.13 it returns False.
This seems wrong to me. Most path-manipulation functions transparently treat symlinks as if they were the pointed-to object unless you pass an option/flag specifically to say you want the symlink itself.
Gonna have to dig to see what else I can find.
#pathlib #path #is_mount #stdlib #behaviour #symlink #filesystem #mountpoint #mount
-
How to Clean Up Your Broken Symlinks: The Good Way and the Better Way
https://www.howtogeek.com/how-to-clean-up-your-broken-symlinks/
-
How to Clean Up Your Broken Symlinks: The Good Way and the Better Way
https://www.howtogeek.com/how-to-clean-up-your-broken-symlinks/
-
#blue_team #WindowsDefender #symlink
- Право `Create symbolic links (SeCreateSymbolicLinkPrivilege)` должно быть только у администраторов. На рабочих станциях выключите `Developer Mode`, чтобы юзеры без прав администратора не могли создавать symlink-и.
- Включите `Tamper Protection` в `Microsoft Defender` и `WDAC/AppLocker`, разрешайте запуск только из подписанных, ожидаемых путей, а не из «любой» папки.
- Проверьте `ACL` каталога платформы `Defender` — право записи должны иметь только `SYSTEM/TrustedInstaller`.
Самый надежный способ обезвредить этот приём — лишить злоумышленника права создавать ссылки, а также детектировать любые попытки трогать каталоги платформы Defender.
-
#red_team #WindowsDefender #symlink
- После выполнения команда создает объект в `C:\ProgramData\Microsoft\Windows Defender\Platform\` с именем `5.18.25070.5-0`. Но этот «каталог» на самом деле является указателем, при обращении к которому система перенаправляет все операции в `C:\TMP\AV`.
- Defender при старте выбирает «самую свежую» подпапку своей платформы по строке версии. И когда он попытается скачать и распаковать обновления, записать служебные файлы или обратиться к своим конфигурациям, операции будут выполняться не в его оригинальном каталоге, а в подложном.
За счет того, что Defender «верит» системному пути, подмена сохраняется до тех пор, пока ссылка не будет обнаружена.
Подробности (https://www.zerosalarium.com/2025/09/Break-Protective-Shell-Windows-Defender-Folder-Redirect-Technique-Symlink.html).
-
#red_team #WindowsDefender #symlink
- Создаем директорию, которую полностью контролируем, например: `C:\TMP\AV`. В нее в дальнейшем будет перенаправлен антивирус. Здесь можно размещать любые файлы — фейковые обновления, бинарники, заглушки, DLL-библиотеки и не только.
- Создаем `symlink` с защищенного пути на контролируемую директорию. Для Defender она будет выглядеть как «правильное» расположение.
То есть адрес легитимной рабочей папки оформляется по принципу: ProgramData\Microsoft\Windows Defender\Platform\[Version-Number]. Нужно создать контролируемую директорию с папкой, название которой соответствует последней версии Defender (это важно). Вот пример консольной команды — `mklink /D "C:\ProgramData\Microsoft\Windows Defender\Platform\5.18.25070.5-0" "C:\TMP\AV"`.
-
Обманываем Windows Defender при помощи symlink
#red_team #WindowsDefender #symlink
Windows разрешает следование по символическим ссылкам, а сам Defender автоматически использует содержимое папки, независимо от того, реальная это папка или ссылка, если название соответствует последней версии программы.
Для работы нам нужен профиль с правами, позволяющими создавать symlink.
-
-
-
La nueva actualización de Windows incluye un fallo de seguridad crítico https://blog.elhacker.net/2025/04/nueva-actualizacion-windows-symlink-bug-cve.html #symlink #Windows #cve
-
La nueva actualización de Windows incluye un fallo de seguridad crítico https://blog.elhacker.net/2025/04/nueva-actualizacion-windows-symlink-bug-cve.html #symlink #Windows #cve
-
💡 Falla di sicurezza in WinRAR bypassa il MotW di Windows
https://gomoot.com/falla-di-sicurezza-in-winrar-bypassa-il-motw-di-windows/
#blog #bug #cve #falla #news #picks #sicurezza #symlink #tech #tecnologia #winrar #zip
-
💡 Falla di sicurezza in WinRAR bypassa il MotW di Windows
https://gomoot.com/falla-di-sicurezza-in-winrar-bypassa-il-motw-di-windows/
#blog #bug #cve #falla #news #picks #sicurezza #symlink #tech #tecnologia #winrar #zip
-
#TIL about the `namei` tool which is sort of like #traceroute but for filesystem traversal.
This is especially useful on #nixos where you're frequently dealing with stuff that is multiple levels of symlinks deep.
It's probably already on your system because it's part of #utillinux; go try it out:
namei `which ls`
-
#SymLink: In this video, Jon Myer asks the AppDev Field Day 2 delegates for their reaction to Codiac's presentation. #_JonMyer #CodiacIO #ADFD2 #Video #JABenedicic #MikeStanley #Mistwire #GuyCurriersFeed
https://www.youtube.com/v/Nmwm30rtGjs -
#SymLink: In this video, Jon Myer asks the AppDev Field Day 2 delegates for their reaction to Codiac's presentation. #_JonMyer #CodiacIO #ADFD2 #Video #JABenedicic #MikeStanley #Mistwire #GuyCurriersFeed
https://www.youtube.com/v/Nmwm30rtGjs -
#SymLink: Learn how to install Nzyme on a WLANPi to monitor and enhance Wi-Fi security, detecting threats and malicious devices efficiently.
https://wifivitae.com/2024/12/06/howto-nzyme/ -
#SymLink: Learn how to install Nzyme on a WLANPi to monitor and enhance Wi-Fi security, detecting threats and malicious devices efficiently.
https://wifivitae.com/2024/12/06/howto-nzyme/ -
#SymLink: Codiac's updated container management platform enhances SDLC collaboration by simplifying Kubernetes complexities and improving DevOps integration. #WriterOfTech1 #CodiacIO #ADFD2 #PlatformEngineering
https://platformengineering.com/social-x/codiac-refreshes-container-management-across-sdlc-some-key-features-on-the-platform/ -
#SymLink: SC24 saw record attendance and spotlighted AI's growing influence in HPC, with a focus on sustainability and the debut of El Capitan as the fastest supercomputer.
https://blog.glennklockwood.com/2024/12/sc24-recap.html -
#SymLink: Kubernetes is viewed as both invaluable and overly complex, fitting for large-scale operations but often excessive for smaller projects.
https://discoposse.com/2024/11/27/kubernetes-a-love-letter-to-complexity-or-a-hatred-for-cloud-chaos/ -
#SymLink: Codiac's updated container management platform enhances SDLC collaboration by simplifying Kubernetes complexities and improving DevOps integration. #WriterOfTech1 #CodiacIO #ADFD2 #PlatformEngineering
https://platformengineering.com/social-x/codiac-refreshes-container-management-across-sdlc-some-key-features-on-the-platform/ -
#SymLink: SC24 saw record attendance and spotlighted AI's growing influence in HPC, with a focus on sustainability and the debut of El Capitan as the fastest supercomputer.
https://blog.glennklockwood.com/2024/12/sc24-recap.html -
#SymLink: Kubernetes is viewed as both invaluable and overly complex, fitting for large-scale operations but often excessive for smaller projects.
https://discoposse.com/2024/11/27/kubernetes-a-love-letter-to-complexity-or-a-hatred-for-cloud-chaos/ -
#SymLink: Concerns rise over Microsoft's Azure security as restricted logging features in pricier plans may compromise data protection.
https://yobyot.com/cloud/will-microsoft-make-customers-more-secure/2024/11/29/ -
#SymLink: Concerns rise over Microsoft's Azure security as restricted logging features in pricier plans may compromise data protection.
https://yobyot.com/cloud/will-microsoft-make-customers-more-secure/2024/11/29/ -
#SymLink: Platform engineering is becoming the new focus in tech, overtaking traditional DevOps by prioritizing operational efficiencies.
https://pivotnine.com/blog/platform-engineering-is-the-new-devops/ -
#SymLink: The blog post explores iOS 18's new security feature that restarts the device after inactivity to safeguard against threats.
https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html -
#SymLink: Platform engineering is becoming the new focus in tech, overtaking traditional DevOps by prioritizing operational efficiencies.
https://pivotnine.com/blog/platform-engineering-is-the-new-devops/ -
#SymLink: The blog post explores iOS 18's new security feature that restarts the device after inactivity to safeguard against threats.
https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html -
#SymLink: Michael Levan's guide demonstrates how to containerize a WASM-based Go application using Docker, highlighting WASM's role as a runtime in cloud environments.
https://dev.to/thenjdevopsguy/wasm-and-docker-quickstart-15pl -
#SymLink: Michael Levan's guide demonstrates how to containerize a WASM-based Go application using Docker, highlighting WASM's role as a runtime in cloud environments.
https://dev.to/thenjdevopsguy/wasm-and-docker-quickstart-15pl -
#SymLink: Stephen Foskett discusses the dual role of acquisitions in IT, highlighting both growth opportunities and innovation risks. @GestaltIT @sfoskett #CFD21
https://gestaltit.com/podcast/stephen/company-acquisitions-are-a-necessary-evil-in-enterprise-tech/ -
#SymLink: Stephen Foskett discusses the dual role of acquisitions in IT, highlighting both growth opportunities and innovation risks. @GestaltIT @sfoskett #CFD21
https://gestaltit.com/podcast/stephen/company-acquisitions-are-a-necessary-evil-in-enterprise-tech/ -
#SymLink: SOUTHWORKS discusses the shift to multi-cloud approaches, emphasizing cloud-agnostic solutions for cost savings and enhanced flexibility. #WriterOfTech1 #SOUTHWORKS #ADFD2 #DevOpsDotCom
https://devops.com/southworks-cloud-agnostic-platforms-will-drive-new-possibilities-in-multi-cloud/ -
#SymLink: SOUTHWORKS discusses the shift to multi-cloud approaches, emphasizing cloud-agnostic solutions for cost savings and enhanced flexibility. #WriterOfTech1 #SOUTHWORKS #ADFD2 #DevOpsDotCom
https://devops.com/southworks-cloud-agnostic-platforms-will-drive-new-possibilities-in-multi-cloud/ -
#SymLink: The article "Nile Campus Full-Service NAAS" explores the comprehensive Network-as-a-Service offerings at the Nile Campus, emphasizing their innovative IT solutions. #PJWelcher #NileSecure #MFD12 #LinkedIn
https://www.linkedin.com/pulse/nile-campus-full-service-naas-peter-welcher-wnjae/ -
#SymLink: The article "Nile Campus Full-Service NAAS" explores the comprehensive Network-as-a-Service offerings at the Nile Campus, emphasizing their innovative IT solutions. #PJWelcher #NileSecure #MFD12 #LinkedIn
https://www.linkedin.com/pulse/nile-campus-full-service-naas-peter-welcher-wnjae/ -
#SymLink: Ben Thompson discusses how generative AI acts as a bridge in the evolution from mainframes to intuitive wearable tech, enhancing user interaction.
https://stratechery.com/2024/the-gen-ai-bridge-to-the-future/ -
#SymLink: Ben Thompson discusses how generative AI acts as a bridge in the evolution from mainframes to intuitive wearable tech, enhancing user interaction.
https://stratechery.com/2024/the-gen-ai-bridge-to-the-future/ -
#SymLink: Itential's new Automation as a Service enhances script and workflow efficiency with a hybrid cloud platform and user-friendly interface. @pjwelcher #PJWelcher #Itential #NFD36 #LinkedIn
https://www.linkedin.com/pulse/nfd36-itential-automation-service-peter-welcher-crgae/ -
#SymLink: Itential's new Automation as a Service enhances script and workflow efficiency with a hybrid cloud platform and user-friendly interface. @pjwelcher #PJWelcher #Itential #NFD36 #LinkedIn
https://www.linkedin.com/pulse/nfd36-itential-automation-service-peter-welcher-crgae/ -
#SymLink: Cisco introduces new Wi-Fi 7 access points with UWB and URWB, enhancing connectivity and location detection, with AI-driven management. @pjwelcher #PJWelcher #Cisco #MFD12 #LinkedIn
https://www.linkedin.com/pulse/cisco-wi-fi-7-announcements-peter-welcher-usgke/ -
#SymLink: Cisco introduces new Wi-Fi 7 access points with UWB and URWB, enhancing connectivity and location detection, with AI-driven management. @pjwelcher #PJWelcher #Cisco #MFD12 #LinkedIn
https://www.linkedin.com/pulse/cisco-wi-fi-7-announcements-peter-welcher-usgke/ -
#SymLink: Mike Stanley reflects on his rewarding first Tech Field Day experience, highlighting Heroku's developer-centric innovations and managed service benefits. #MikeStanley #Heroku #ADFD2
https://mikestanley.me/2024/11/26/app-dev-2-heroku/ -
#SymLink: Mike Stanley reflects on his rewarding first Tech Field Day experience, highlighting Heroku's developer-centric innovations and managed service benefits. #MikeStanley #Heroku #ADFD2
https://mikestanley.me/2024/11/26/app-dev-2-heroku/ -
#SymLink: Meter showcased its integrated networking solutions at Networking Field Day 36, emphasizing innovation and customer-aligned service models. #Meter #NFD36
https://www.meter.com/blog/networking-field-day-36