3 ms·
Exactly right re: doing it downstream (or in the case of virtual machines, outside of the guest). I didn't mean 'intend' in the context of unauthorised use, i
by sturadnidge 13y ago
Exactly right re: doing it downstream (or in the case of virtual machines, outside of the guest).
I didn't mean 'intend' in the context of unauthorised use, i was trying to differentiate between a 'single user' ( can't think of a better term, but i'm sure you know what i mean) application server and systems where you purposefully give shell access to other users but want to restrict egress.
- jacquesm 13y agoSystems like that are only a privilege escalation away from being compromised and are much softer targets. Anything with shell access for multiple parties not known intimately to the owner of the box should be monitored with great zeal.