“Hand of Thief” Trojan Targets Linux
blogs.rsa.com
blogs.rsa.com
It is not a real remote exploit due to any flaw in Linux, rather it is something the purveyors trick people into installing via "social engineering".
One very simple way to get a sandboxed browser is to run this command (my irony meter is going off the charts here):
sandbox -X -t sandbox_web_t firefox
However, that will prevent any persistence between sessions, so you probably want to do something more like this:
sandbox -X -H /path/to/some/directory -t sandbox_web_t firefox
My recommendation is that you read the man pages and experiment a bit.
Nothing wrong with showing commands and examples to be used. It's the cut-and-paste aspect that's an issue.
My first action was to search through my package repos (Debian) to see if that sandbox command is known to my packaging system (it's not, hrm...).
Nothing is safe.
curl http://example.com/install.sh | shInstalling rvm shouldn't add lines to my .zshrc without prompting me. That behavior would be outrageous anywhere else but in Ruby land it's normal.
Switch to that user before running any code you are not sure about.
LD_PRELOAD? ptrace?
I googled but only found ways of doing this that are Win32-specific.