QuestionQ19

Security Operations

A SOC analyst is investigating an incident in which a penetration tester successfully created and executed a payload. The analyst retrieves the following command history from the impacted server:

$ uname -a && env  
$ vim foo.c  
$ gcc foo.c /tmp/lockfile  
$ chmod +x /tmp/lockfile  
$ ./tmp/lockfile  

Which of the following should the analyst implement to enhance the server's security?

Explanation

Globally writable directories such as /tmp should have execution restricted, commonly with a noexec mount option. This prevents an attacker from compiling or depositing a payload in the directory and then running it from there.

Community Discussion

No comments yet. Be the first to start the discussion!