Hacker News new | past | comments | ask | show | jobs | submit login

Yep. I had no idea sourced scripts don’t need execute. Once they were pushing files up there I snarked to myself “psshhhh good luck running them!”



If he could get to a bash prompt or get exec() access he could run scripts without +x too...

exec('bash path/to/supposedly/unexecutable/script.sh')


Yeah - is this a security issue?


Considering that’s what they used for bringing up dropbear. I would think yes!




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: