3 ms·
>all you get is the possibility to [...] execute code Anyone who's ever done even a beginner CTF knows that achieving code execution is a big deal.
by stackghost 2mo ago
>all you get is the possibility to [...] execute code
Anyone who's ever done even a beginner CTF knows that achieving code execution is a big deal.
- pixl97 2mo agoYep, once you have code execution you find a local privilege escalation and go from there.
- emj 2mo agoThe point is you can not trust that people patch stuff like this in time. So practically you have to make it really hard, in a CTF of course it is easy. Defense is in depth. There are architectural issues, e.g. we only allow one upload per instance., and sanitation is done away from initial upload handling and processing. I would say that even local root is not that bad if you play your cards correctly. (What ever root mean nowdays with CAP dropping etc) Enterprise security can be good if people are paranoid when they build the infra, but as is highlighted in this thread many patch requirements are stupid.