3 ms·
If the site is really simple and just runs system() on a VPS, chances are that there is no protection against command injection, server takeovers, and worse. So
by justusw 4y ago
If the site is really simple and just runs system() on a VPS, chances are that there is no protection against command injection, server takeovers, and worse. So what comes from good intentions might end up causing a lot of harm.
The problem of shadow IT is very real and should best be countered with a healthy amount of education. And whitelisting instead of black listing as the default approach.
- ipaddr 4y agoChances are? Very unlikely as these things run in a vm that dies when the request is finished. I would be more worried about the big player who do scan your documents and share with government entities. People are scared of the[unknown when the known is more likely
- gjsman-1000 4y ago> as these things run in a vm that dies when the request is finished You don't know that. There's absolutely no reason why they need to run that way. They could be literally saving all of your upload files permanently, and running on Linux from 6 years ago with 17 backdoors, and there's no way to know that. There is nothing requiring them to run in a VM - they could easily be colocated bare metal. Dies when the request is finished? PHP works that way, but NodeJS doesn't, and either programming language can easily save your files to any other location like an S3 bucket. Dies when the request is finished is completely irrelevant here.
- ipaddr 4y agoThey can save your files and millions of other files. Then what? Setup a global ad network and use that information to provide targeted ads? My point is these big companies can do a lot more damage. Trust no one online.