[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debconf and noexec on /tmp



On Thu, Nov 08, 2001 at 03:43:56PM +0100, Wichert Akkerman wrote:
> Previously Ethan Benson wrote:
> > its not, it provides you NO extra security whatsoever, and will break
> > many many things.
> 
> It breaks a fair number of scripts that script-kiddies use, and as
> such it is somewhat useful.

1: if your system is vulnerable to script kiddies then admin needs to
   be taken out back and beaten with a large LART.

2: if the script kiddie even has 2 tenths of a percent of clue he will
   figure out how to move the file somewhere else, or use my earlier
   mentiond ld//bin/sh method of execution.

its security through obscurity IMO, and a waste of time.

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgp56lVQQWJGy.pgp
Description: PGP signature


Reply to: