我有一个asp.net 3.5应用程序,可以将zip文件写入目录(Ionic zip-lib)。这让我的客户端担心这可能会打开服务器进行攻击。他的逻辑是:
- my app uses ASPNET account to write the file
- ASPNET is a shared account that is used by other apps on the same server.
- therefore it could be dangerous to use it to write files. he didnt go into details.
这是真的吗?如果是,什么样的攻击?我该如何预防?