Re: [Security-Discuss] Exploits

"Bob Puff@NLE" <bob-6dd4Sf22++lWk0Htik3J/[email protected]> Mon, 10 Apr 2006 13:50:08 -0400
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
I also noticed that the user apache has a /bin/sh for a shell.  A redhat machine I checked had 
apache with a /bin/false shell.  Should this be done too?

Bob

Marko Vukovic wrote:

> On Tue, 2006-04-04 at 02:22 -0400, Bob Puff wrote:
> 
>>Hi Vince (& all),
>>
>>I did manage to find the point of entrance; and you were right - it wasn't
>>mod_ssl.  It was someone's WebCalendar, which is quite a hole it seems unless
>>you're running the latest and greatest.
> 
> 
> Often these exploits run their binaries (as Apache user) from /tmp 
> An easy first step in preventing many attacks is to mount your /tmp
> partition noexec.
> 
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________