Is privilege escalation that easy/common? Thinking esp of the number of shared hosting providers out there, if a user account is compromised they don't assume the entire server is compromised.
Privilege escalation is easier than getting the initial shell. I would certainly reinstall any machine where someone has a shell.
As for these web shells, this agin demonstrates the important of blocking outbound connections with a firewall or some type of networking design.
Comments
Privilege escalation is easier than getting the initial shell. I would certainly reinstall any machine where someone has a shell.
As for these web shells, this agin demonstrates the important of blocking outbound connections with a firewall or some type of networking design.