• groet
    link
    fedilink
    English
    arrow-up
    73
    ·
    4 days ago

    No, why would it? It will run code in the context of the current user which is absolutely enough to start a new process that will run in the background, download more code from a attacker server and allow remote access. The attacker will only have as much permissions as the user executing the code but that is enough to steal their files, run a keyloggers, steal their sessions for other websites etc.

    They can try to escalate to the admin user, but when targeting private victims, all the data that is worth stealing is available to the user and does not require admin privs.

      • schizo@forum.uncomfortable.business
        link
        fedilink
        English
        arrow-up
        18
        arrow-down
        1
        ·
        4 days ago

        This here. The most important thing on your computer are all your session cookies, which are, well, accessible with permissions your user account already has.

        Dudes don’t care about making your shit into a botnet, or putting a rootkit in your firmware, or whatever other technically complex thing you care to think about: they’re there to steal your shit, and the most valuable shit you have is sitting there out in the open for the taking for anyone who makes it past a very very low bar of ‘make the user do something stupid’.

    • Avid Amoeba@lemmy.ca
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      edit-2
      4 days ago

      Exactly. The moment you hit Enter, the computer becomes part of a botnet on every login.