Malware

Remote code execution

Also called RCE.

Remote code execution is when an attacker makes your server run code they chose, from the network, without being logged in as you. It is the point where a bug becomes a takeover.

How it is measured

It is not measured as a rate; you confirm a path exists. Evidence: a CVE entry tagged RCE for something you run, a request in the logs carrying shell syntax or a serialized object, an unexpected child process spawned by your web server such as sh or curl, or a new file written by the web user.

Test your own system only in staging, using the vendor's check or a harmless command with a timing difference such as sleep. Review server logs for the same string across the days before you noticed.

Worked example

A Laravel app at a small SaaS runs an old debug-mode package. The access log has a request to /_ignition/execute-solution with a JSON body referencing a file path. Within a minute the process list shows php-fpm spawning bash and then wget fetching a .sh file from an unfamiliar host.

The attacker never had an account. The log line plus the child process is the proof. The team takes the host offline, rotates the app key and database password because the process could read .env, and rebuilds from a clean image.

How it differs

SQL injection makes the database execute attacker-chosen queries; the attacker is limited to what the database account can do, though that can sometimes be stretched into command execution. Remote code execution means they are running code in the application or on the OS itself. SQLi often leaks data; RCE usually means full control.

Common errors

Rating the bug by its entry point instead of its consequence. Thinking a web application firewall makes patching optional. Running the web server as root or with write access to its own code. Cleaning the dropped file but not rotating secrets in the environment. Assuming an unauthenticated RCE needs a targeted attacker, when scanners find it for them.

In practice

Patch the affected component first, then assume secrets in reach of the process are burned and rotate them. Run the web process as a low-privilege user, make the code directory read-only to it, and alert on shell binaries spawned by the web server.

See also

SQL injection, Webshell

Sources

Count this on a real site.

Watch my website