Hacker News new | ask | show | jobs
by andrewflnr 4472 days ago
WRT local shells, it might well be a good idea to assume someone who got a shell as apache could use a privilege escalation 0-day and do some more damage. Hopefully your deployment process is such that starting from scratch isn't a huge hardship. I'd appreciate of someone with actual security experience (not me) weighed in...
1 comments

It's very naive to think that you can protect a box from somebody with a local shell. Never worked.