Re: siege failing and so on

[email protected] Sun, 12 Oct 2003 20:27:13 +0200
Newsgroups gmane.comp.apache.metuxmpm
Message-ID <[email protected]>
-                                                 [email protected]
---------------------------------------------------------------------

On Sun, Oct 12, 2003 at 07:56:27PM +0200, Asbj?rn Sannes wrote:

<snip>
> > hmm, perhaps we could do a little trick. Let an watch process ptrace
> > the processors. This would prevent the attacker from ptracing it and will
> > ensure that he cannot put its own code into the webserver process.
> > How many resources will this consume ?
> 
> Linux has CAP_PTRACE to do this, right?
hmm, is the capability support enabled by default ?
we could use it if available and print out a warning when not.

<snip>
> > Another problem is preventing the processor from hurting itself
> > (exploiting mod_php, etc). Is it possible to prevent an process from
> > overwriting its own code ?
> 
> This isn't really the job of apache? (stopping modules from doing things 
> wrong is taking it a bit far, what if that is the purpose of the module .. 
> and so on :> ). There are patches for the kernel (for linux) that does 
> these things tough. 
I dont think of accidents, but of explicit overwriting of running code.
(perhaps with the help of the kernel or libc). Other processes on the 
host might still be able to do it, but in the processor it would be nice
if it were impossible to hook into the mpm code. Well, of course its also
an unclean patchwork just as php's safe mode.

cu
-- 
---------------------------------------------------------------------
 Enrico Weigelt    ==   metux IT services

 phone:     +49 36207 519931         www:       http://www.metux.de/     
 fax:       +49 36207 519932         email:     [email protected]
 cellphone: +49 174 7066481	     
---------------------------------------------------------------------
 Diese Mail wurde mit UUCP versandt.      http://www.metux.de/uucp/