Hacker News new | ask | show | jobs
by bigiain 5523 days ago
True. But a _properly evil_ non-suicidal and supremely confident evil DBA could, if they wanted too, exploit the box from a local user account, rootkit it, and tidy up after themselves to remove all trace of who did it. I suspect that's actually script-kiddy-able these days, if you know the target well enough there's probably an automated tool ready to do all that for you.

(For evil-genius-DBA's bonus points for doing that via the database instead of the shell and censoring traces from the db logs too...)