Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




firewall-wizards logo Firewall Wizards mailing list archives

Re: Securing a Linux Firewall
From: Brian Hatch <firewall-wizards () ifokr org>
Date: Tue, 23 Jul 2002 14:12:30 -0700



s/can/may be able to/, it depends on the ammount of space the attacker has 
to work with- also the attacker may only have write access to a 
noexec/nodev filesystem.

A noexec filesystem won't help.  Say you have /noexec mounted
with (duh) noexec.  That protects you from running

        $ /noexec/path/to/program
but not
        $ sh /noexec/path/to/shellscript
or
        $ /lib/ld-linux.so.2 /noexec/path/to/program

for example.

(Not that noexec isn't a good idea - it's just not a silver bullet.)

--
Brian Hatch                  "Enjoy your time with the
   Systems and                perpetual motion machine
   Security Engineer          you call a daughter"
www.hackinglinuxexposed.com  --Stephen Entwisle

Every message PGP signed

Attachment: _bin
Description:


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]