Re: [Security-Discuss] Exploits

Marko Vukovic <[email protected]> Mon, 10 Apr 2006 01:58:05 +0200
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Tue, 2006-04-04 at 02:22 -0400, Bob Puff wrote:
> Hi Vince (& all),
> 
> I did manage to find the point of entrance; and you were right - it wasn't
> mod_ssl.  It was someone's WebCalendar, which is quite a hole it seems unless
> you're running the latest and greatest.

Often these exploits run their binaries (as Apache user) from /tmp 
An easy first step in preventing many attacks is to mount your /tmp
partition noexec.

-- 
Marko

____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________