arget13 / DDexec

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
GNU General Public License v3.0
798 stars 83 forks source link

Not work with google cloud shell #12

Closed hugeintimate closed 1 year ago

hugeintimate commented 1 year ago

i use google cloud shell environment but it doesn't work

hugeintimate commented 1 year ago

Screenshot_20230321_101223_Chrome

arget13 commented 1 year ago

Hello, thank you for your feedback. That behaviour isn't due to an error or bug in DDexec, it's because that system is hardened against this technique and there's nothing else we can do!

arget13 commented 1 year ago

What I would really like to learn is how they managed to make the mem file readonly. imagen