Re: Systems compromised with ShellBOT perl script - part 2
From: Thomas Hochstein (ml_at_ancalagon.inka.de)
Date: 10/21/04
- Previous message: Nick FitzGerald: "Re: DoS worm"
- In reply to: Stephen J. Smoogen: "Re: Systems compromised with ShellBOT perl script - part 2"
- Next in thread: Paul Schmehl: "Re: Systems compromised with ShellBOT perl script - part 2"
- Reply: Paul Schmehl: "Re: Systems compromised with ShellBOT perl script - part 2"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: incidents@securityfocus.com Date: Thu, 21 Oct 2004 11:00:01 +0200
"Stephen J. Smoogen" schrieb:
> I would check to make sure that none of the
> PHP/perl/etc are defaulting to using /tmp as their "temp space" as
> that would avoid the noexec,nosuid.
To have a look at those Perl/PHP-scripts wouldn't hurt either; there
are enough remote code injection exploits to be found in more or less
standard PHP applications.
-thh
- Previous message: Nick FitzGerald: "Re: DoS worm"
- In reply to: Stephen J. Smoogen: "Re: Systems compromised with ShellBOT perl script - part 2"
- Next in thread: Paul Schmehl: "Re: Systems compromised with ShellBOT perl script - part 2"
- Reply: Paul Schmehl: "Re: Systems compromised with ShellBOT perl script - part 2"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|