3 ms·
>Always run services (e.g. ElasticSearch) with a unique user dedicated to that service and nothing else. Quick tip; If you do this, you can also make your ipta
by voidlogic 10y ago
>Always run services (e.g. ElasticSearch) with a unique user dedicated to that service and nothing else.
Quick tip; If you do this, you can also make your iptables rules be per user. For example, "webserverUser" can only accept inbound connections on 80/443 and only have outbound connections that are related to established inbound ones. If an attacker gains execution as this user, they cannot download new code, etc or even do DNS lookups for that matter.
- breakingcups 10y agoWow, that's great, I never considered doing that. Thanks!
- startling 10y agoIt's only marginally helpful: it doesn't actually prevent attackers from uploading code to your server. Instead of having 'nc -l 8080 | bash' or whatever as your payload, an attacker can just run code instead. "pwd > /var/www/html/exfiltration.html". If they absolutely need a shell, they could e.g. alter nginx or its config files to run `bash` on POSTs to a hidden route. This does make it a little trickier, and potentially a little easier to detect. But it certainly doesn't make it so that "they cannot download new code".
- voidlogic 10y ago>This does make it a little trickier, and potentially a little easier to detect. Correct, I should have said, it eliminates many easy ways to download code. Defense is depth is all about making the attackers job harder and increasing their likelihood of being detected.
- startling 10y agoThis is totally wrong. Once you have RCE, you can upload code the same way you're executing code.