Answer the question
In order to leave comments, you need to log in
FTP access to server subdirectory = root?
Once I was a victim of Chinese hackers (they hacked a server through an outdated phpmailer - a vulnerability through the 5th sendmail parameter), I thought, how can I now safely give someone ftp access to a particular server directory? After all, an attacker can upload a backdoor there in no time and get root, or am I wrong?
Answer the question
In order to leave comments, you need to log in
By uploading it to the "backdoor" folder, the alleged attacker will be able to run any scripts on behalf of the web server. Well, or on behalf of php-fpm, for example. Shell scripts will run under the same name. Therefore, "getting root" is not possible by default.
The presence of chroot in ftp, in its essence, destroys the described problem in the bud.
BUT! All of the above is true in the absence of an exploit of critical kernel vulnerabilities. Therefore, if there are current security updates.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question