课程: Programming Foundations: Web Security

今天就学习课程吧!

今天就开通帐号,24,600 门业界名师课程任您挑!

Remote system execution

Remote system execution

- There is one attack that's worse than all the others. Remote code execution. Remote code execution or RCE is when an attacker can remotely execute Internal operating system commands on a server. To put it another way, an attacker can type commands as if they were sitting at the keyboard. They can perform any task a logged in user could perform. They can read, add, modify, or delete files. They can change access privileges or passwords. They can turn on and off configurations and services and they can communicate to other servers. When you read a news article or see a warning about a bug, which allows remote code execution, you should pay attention. It is a significant one. Fortunately, remote code execution is also one of the hardest hack to pull off. Operating systems keep a wall between the operating system and the software running the web server, which is difficult to get through. That is, unless you make it easy.…

内容