Re: siege failing and so on
[email protected] Sun, 12 Oct 2003 19:41:18 +0200
| Newsgroups | gmane.comp.apache.metuxmpm |
|---|---|
| Message-ID | <[email protected]> |
- [email protected] --------------------------------------------------------------------- On Sun, Oct 12, 2003 at 07:22:48PM +0200, Asbj?rn Sannes wrote: <snip> > I've been thinking about this for a while, on a production webserver, can we > not stop people from attaching stuff to processes in the OS? hmm, perhaps we could do a little trick. Let an watch process ptrace the processors. This would prevent the attacker from ptracing it and will ensure that he cannot put its own code into the webserver process. How many resources will this consume ? Another problem is preventing the processor from hurting itself (exploiting mod_php, etc). Is it possible to prevent an process from overwriting its own code ? cu -- --------------------------------------------------------------------- Enrico Weigelt == metux IT services phone: +49 36207 519931 www: http://www.metux.de/ fax: +49 36207 519932 email: [email protected] cellphone: +49 174 7066481 --------------------------------------------------------------------- Diese Mail wurde mit UUCP versandt. http://www.metux.de/uucp/