4 ms·
> If he had used a separate non-root account for Redis, the damage would have been limited to that single user account. Probably not. The attacker would have g
by repomies69 11y ago
> If he had used a separate non-root account for Redis, the damage would have been limited to that single user account.
Probably not. The attacker would have gotten access to the machine. As there is a lot of software installed locally some probably have holes, which allows for full root access.
So I don't really believe it makes much difference for serious attacker if the attacker gets root access or normal access.
- eeZi 11y agoIt's not that easy to get a local privilege escalation on an up-to-date system.