4 ms·
> This change now means that in the future if an attacker were to exploit some previously unknown vulnerability in a given system service that is running as a s
by towergratis 5y ago
> This change now means that in the future if an attacker were to exploit some previously unknown vulnerability in a given system service that is running as a separate user, they would then not be able to access the data of any other user (both human or system service) on the system.
If the attacker can already access arbitrary files on your box, I don't think simple unix permissions will save you
- deadbunny 5y agoSo let's just set everything to 777? /s
- towergratis 5y agoAll I am saying is that security is like onion layers, and unix permissions are the last layer probably. If the attacker penetrated through all the other layers, chances are that unix permissions will not save you.
- asah 5y agogoogle.com/search?q=defense+in+depth
- sillysaurusx 5y agoFormer pentester here. It was often the case that we were able to penetrate a box as a low-level user account, and the way we escalated was to search ~/.bash_history of an admin account. chmod'ing the homedir would've prevented that. Unix happens to be pretty good about directory permissions.
- boring_twenties 5y agoThe .bash_history file is mode 0600, regardless of directory permissions. Was this not always the case?
- sillysaurusx 5y agoHeh. Looks like I’ve been out of the game longer than I thought. It’s suddenly been 6 years. Welp. Yes, I misremembered that specific example. Still, you’d be amazed how often people leave json credentials in their homedir that can be used to pivot to e.g. S3.
- bombcar 5y agoThe number of bash history files with accidental passwords pasted into them is quite high. Another reason I don’t sudo and instead ssh
- throwawayboise 5y agoShell history files for admin accounts should be disabled (or at least kept short) for this reason.
- jcpham2 5y agoBut I really really like shell history files if I have to come behind someone!
- bombcar 5y agoInteresting idea - make it so all your passwords start with the same four characters (say Ab54) - (it's hard to get good passwords you can safely type at a prompt anyway) and then have a script that searches your history/log files for strings beginning with the Ab54 characters and replacing them with XXXX or similar. All sorts of horrible side effects can immediately be identified.
- megous 5y agoThat's what they are for, though.