4 ms·
True, yet in a few cases the not-dropping of privileges is a real risk, like with `less` [0], which allows for arbitrary shell access despite being meant for fo
by matthberg 5y ago
True, yet in a few cases the not-dropping of privileges is a real risk, like with `less` [0], which allows for arbitrary shell access despite being meant for for just paging. Also, it's useful to know that a program is sloppy with permissions in case any bugs are found in it; a CS prof I once had always insisted we dropped permissions and capabilities as soon as we were done with them so that any calls to other libraries or our own buggy code could do the least damage possible, just like how it's good practice to not run every command as root.
[0]: https://gtfobins.github.io/gtfobins/less/ https://gtfobins.github.io/gtfobins/less/
- JohnFen 5y ago> a CS prof I once had always insisted we dropped permissions and capabilities as soon as we were done with them Only once?? Doing this should be muscle memory for working devs.