3 ms·
It’s a single process running inside a sandboxed VM. That process might not have code written for reading files from disk (let alone writing them) or a full TC
by pushpop 7y ago
It’s a single process running inside a sandboxed VM. That process might not have code written for reading files from disk (let alone writing them) or a full TCP/IP stack (let alone the ability to forward SSH sessions) and it certainly wouldn’t have any capabilities of launching a remote shell. So you’re not going to be susceptible to the vast majority RCE vulnerabilities that happen with even a minimal GNU/Linux port. Even if sloppy C++ coding did make you vulnerable, you’re still stuck inside the VM with literally nothing available aside that process.
The bigger risk is DDoS attacks but that’s risk when writing sloppy code in any language, runtime and hosting environment.