If some can read the process table on your server, you are already screwed. There are literally dozens of local privilege escalation exploits on linux.
But, if you dont want to set a password in the calibre server, reverse proxy it behind apache or nginx or whatever. Instructions on how to reverse proxy are in the user manual.
|