Trojan attacks can be made by placing commonly used commands (such as ls) into a directory in where the the system account (or any privileged account) may execute commands.