[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: phpBB vulnerability exploited



also sprach Jerome Vandenabeele <jerome.vandenabeele_deb@gadz.org> [2004.12.14.1200 +0100]:
> Maybe you could make 2 partitions: /var mounted noexec and
> /var/spool/postfix mounted exec

I hope you are running a 2.6 kernel if you rely on the exec flag.
Sorry for barking into this thread, which I have not followed. When
I see PHP, I say no.

Aren't postinst files also executed from within /var?

-- 
Please do not send copies of list mail to me; I read the list!
 
 .''`.     martin f. krafft <madduck@debian.org>
: :'  :    proud Debian developer, admin, user, and author
`. `'`
  `-  Debian - when you have better things to do than fixing a system
 
Invalid/expired PGP subkeys? Use subkeys.pgp.net as keyserver!

Attachment: signature.asc
Description: Digital signature


Reply to: