3 ms·
I'd be interested in hearing more about the specific for some of these, but others seem unlikely to work. For example, there's no reason for a user to have rea
by staticassertion 5y ago
I'd be interested in hearing more about the specific for some of these, but others seem unlikely to work.
For example, there's no reason for a user to have read, let alone write, access to authorized_keys.
Read and write access for users is way overly permissive by default, but it's really easy to fix that.
I do agree that you can't trust the shell if a user is compromised though. But this is about preventing an attacker from gaining root access, which means you now can't trust the entire system (since they can just shut off security controls).
Also keep in mind that all of these described attacks require performing auditable actions. If an attacker can trivially, quickly escalate, you can't trust your auditing.