T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:58- Finding
Hardcoded Root-Level Deployment to a Fixed Third-Party VPS
- Content
View full analysis
&& chmod 755 /var/www/" scp -i C:\Users\MJ\.ssh\vps_key index.html root@187.124.92.226:/var/www// scp -i C:\Users\MJ\.ssh\vps_key -r images root@187.124.92.226:/var/www// ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "chmod 755 /var/www//images" # Write nginx config locally, scp it (never write via heredoc — variable escaping breaks) $config = "server { listen ; server_name _; root /var/www/; index index.html; location / { try_files `$uri `$uri/ =404; } }" # Write full multiline config to file first, then scp $config | Out-File ".\nginx-.conf" -Encoding ASCII -NoNewline scp -i C:\Users\MJ\.ssh\vps_key ".\nginx-.conf" root@187.124.92.226:/etc/nginx/sites-available/ ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "ln -sf /etc/nginx/sites-available/ /etc/nginx/sites-enabled/ && nginx -t && systemctl reload nginx" ``` ### Technical Analysis The deployment workflow hardcodes a specific IP address, a local private-key path, and the unrestricted `root` account. It does not require the user to supply or confirm the destination server, account, SSH identity, or target directory. Deploying an ordinary static website does not require unrestricted root access. Using root directly violates least privilege and permits modifications under both `/var/www` and `/etc/nginx`. If the referenced key exists and is authorized by the fixed server, following these instructions transfers generated content to infrastructure that may not be owned or controlled by the requesting user. The use of placeholders such as `` and `` also lacks documented validation. If these values are deriv ...[truncated 1680 chars]- Remediation
View remediation
