[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: a weird script worm uploaded via php with debian 3.0 ?



On Wed, 11 Jun 2003, Celso González wrote:

> I dont have any information about your trojan, but i can give you a
> solution (also a good security practice)
>
> Mount /tmp in a separate partition with the noexec flag in fstab
>
> This will disable most of the trojans

Sorry to delude you, but browse the archives: you will find that even with
a noexec partition you can run any executable by just invoking

/lib/ld.so /tmp/yourexecutable

Bye
Giacomo

-- 
_________________________________________________________________

Giacomo Mulas <gmulas@ca.astro.it>
_________________________________________________________________

OSSERVATORIO ASTRONOMICO DI CAGLIARI
Str. 54, Loc. Poggio dei Pini * 09012 Capoterra (CA)

Tel. (OAC): +39 070 71180 248     Fax : +39 070 71180 222
Tel. (UNICA): +39 070 675 4916
_________________________________________________________________

"When the storms are raging around you, stay right where you are"
                         (Freddy Mercury)
_________________________________________________________________



Reply to: