3 ms·
You may already be aware of this, but it's trivial to read a process's environment variables, for any process running as the same user, or when root. They're e
by tene 10y ago
You may already be aware of this, but it's trivial to read a process's environment variables, for any process running as the same user, or when root. They're exposed as a null-delimited text file in /proc/$pid/environ. You can even get ps to print the environment variable for you, if you use the 'e' flag (no leading dash). Depending on your actual security constraints, this may be important to be aware of. Of course, there are a variety of options for reading a process's arbitrary memory locations, so for actual security you need to control accesss to the host, but if you're worried about leaking 'ps' for command line arguments, you should be similarly aware about 'ps' showing environment variables.
- mnarayan01 10y ago"Usually" permissions on /proc/$pid/environ are way more restrictive than on /proc/$pid/cmdline.
- tene 10y agoYep, that's why I mentioned "as the same user". It's slightly less of a risk of data exposure, but it's worth being aware of when evaluating your threat model.