Security Incidents mailing list archives

Re: Systems compromised with ShellBOT perl script - part 2


From: Thomas Hochstein <ml () ancalagon inka de>
Date: Thu, 21 Oct 2004 11:00:01 +0200

"Stephen J. Smoogen" schrieb:

I would check to make sure that none of the
PHP/perl/etc are defaulting to using /tmp as their "temp space" as
that would avoid the noexec,nosuid.

To have a look at those Perl/PHP-scripts wouldn't hurt either; there
are enough remote code injection exploits to be found in more or less
standard PHP applications.

-thh


Current thread: