3 ms·
If the author is truly a "ninja" they wouldn't be running their web application as the nginx www-data user in the first place, and then a web application exploi
by tinix 8y ago
If the author is truly a "ninja" they wouldn't be running their web application as the nginx www-data user in the first place, and then a web application exploit wouldn't inherently give anyone access to the nginx user either to exploit the log-rotation mechanism via symlink. One can read more about the CVE you linked here[1]. But basically the gist of it is this:
> As the /var/log/nginx directory is owned by www-data, it is possible for local attackers who have gained access to the system through a vulnerability in a web application running on Nginx (or the server itself) to replace the log files with a symlink to an arbitrary file.
This assumes the web application is also running as www-data, which wouldn't be that smart.
[1] https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-P...