3 ms·
It's possible to debug targets running under the current user, so root privileges might not have been needed, if they had an agent running under the same UID as
by rainforest 13y ago
It's possible to debug targets running under the current user, so root privileges might not have been needed, if they had an agent running under the same UID as the application.
> However, the private key can be then used to carry out crypto operations.
Surely this is of concern? According to the logs they'd known about the breach for a week - that seems like enough time to decrypt each card one by one and exfiltrate them.