Re: siege failing and so on

[email protected] Sun, 12 Oct 2003 19:41:18 +0200
Newsgroups gmane.comp.apache.metuxmpm
Message-ID <[email protected]>
-                                                 [email protected]
---------------------------------------------------------------------

On Sun, Oct 12, 2003 at 07:22:48PM +0200, Asbj?rn Sannes wrote:

<snip>
> I've been thinking about this for a while, on a production webserver, can we 
> not stop people from attaching stuff to processes in the OS?
hmm, perhaps we could do a little trick. Let an watch process ptrace
the processors. This would prevent the attacker from ptracing it and will
ensure that he cannot put its own code into the webserver process.
How many resources will this consume ?

Another problem is preventing the processor from hurting itself 
(exploiting mod_php, etc). Is it possible to prevent an process from 
overwriting its own code ? 

cu
-- 
---------------------------------------------------------------------
 Enrico Weigelt    ==   metux IT services

 phone:     +49 36207 519931         www:       http://www.metux.de/     
 fax:       +49 36207 519932         email:     [email protected]
 cellphone: +49 174 7066481	     
---------------------------------------------------------------------
 Diese Mail wurde mit UUCP versandt.      http://www.metux.de/uucp/