--=-qdRMs+J0zjXW/jcU/00T Content-Type: text/plain Content-Transfer-Encoding: 7bit
On Sat, 2005-04-09 at 12:47 +0300, Ilya Konstantinov wrote: > Recently quite a few individuals have attempted to break into a server I > manage through a recently-found vulnerability in phpBB. Here's what each > of them attempted: > Attachker #2: Downloading some kind of bot to our /tmp (using wget). For > some strange reason, he hasn't continued the breakin. For that I put /tmp mounted as noexec (maybe you did too and that's why he didn't continue? :)) Plus, just don't put any apache-writable place on the whole system. As for the logs, put them on a different filesystem, and again, mount it noexec. "If they can't execute their stuff...". Of course it's possible to do the above mentioned stuff with other security capabilities, but the concept is what's important. Oh, and by the way... DON'T USE PHPBB :) -- shimi <[EMAIL PROTECTED]> --=-qdRMs+J0zjXW/jcU/00T Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 7bit <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN"> <HTML> <HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; CHARSET=UTF-8"> <META NAME="GENERATOR" CONTENT="GtkHTML/3.2.5"> </HEAD> <BODY> On Sat, 2005-04-09 at 12:47 +0300, Ilya Konstantinov wrote: <BLOCKQUOTE TYPE=CITE> <PRE> <FONT COLOR="#000000">Recently quite a few individuals have attempted to break into a server I </FONT> <FONT COLOR="#000000">manage through a recently-found vulnerability in phpBB. Here's what each </FONT> <FONT COLOR="#000000">of them attempted:</FONT> </PRE> </BLOCKQUOTE> <BR> <BLOCKQUOTE TYPE=CITE> <PRE> <FONT COLOR="#000000">Attachker #2: Downloading some kind of bot to our /tmp (using wget). For </FONT> <FONT COLOR="#000000">some strange reason, he hasn't continued the breakin.</FONT> </PRE> </BLOCKQUOTE> <BR> For that I put /tmp mounted as noexec (maybe you did too and that's why he didn't continue? :))<BR> <BR> Plus, just don't put any apache-writable place on the whole system. As for the logs, put them on a different filesystem, and again, mount it noexec. "If they can't execute their stuff...".<BR> <BR> Of course it's possible to do the above mentioned stuff with other security capabilities, but the concept is what's important.<BR> <BR> Oh, and by the way... DON'T USE PHPBB :)<BR> <BR> <TABLE CELLSPACING="0" CELLPADDING="0" WIDTH="100%"> <TR> <TD> -- <BR> shimi <<A HREF="mailto:[EMAIL PROTECTED]">[EMAIL PROTECTED]</A>> </TD> </TR> </TABLE> </BODY> </HTML> --=-qdRMs+J0zjXW/jcU/00T-- ================================================================= To unsubscribe, send mail to [EMAIL PROTECTED] with the word "unsubscribe" in the message body, e.g., run the command echo unsubscribe | mail [EMAIL PROTECTED]
