--=-qdRMs+J0zjXW/jcU/00T
Content-Type: text/plain
Content-Transfer-Encoding: 7bit

On Sat, 2005-04-09 at 12:47 +0300, Ilya Konstantinov wrote:

> Recently quite a few individuals have attempted to break into a server I 
> manage through a recently-found vulnerability in phpBB. Here's what each 
> of them attempted:



> Attachker #2: Downloading some kind of bot to our /tmp (using wget). For 
> some strange reason, he hasn't continued the breakin.


For that I put /tmp mounted as noexec (maybe you did too and that's why
he didn't continue? :))

Plus, just don't put any apache-writable place on the whole system. As
for the logs, put them on a different filesystem, and again, mount it
noexec. "If they can't execute their stuff...".

Of course it's possible to do the above mentioned stuff with other
security capabilities, but the concept is what's important.

Oh, and by the way... DON'T USE PHPBB :)

-- 
shimi <[EMAIL PROTECTED]>

--=-qdRMs+J0zjXW/jcU/00T
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN">
<HTML>
<HEAD>
  <META HTTP-EQUIV="Content-Type" CONTENT="text/html; CHARSET=UTF-8">
  <META NAME="GENERATOR" CONTENT="GtkHTML/3.2.5">
</HEAD>
<BODY>
On Sat, 2005-04-09 at 12:47 +0300, Ilya Konstantinov wrote:
<BLOCKQUOTE TYPE=CITE>
<PRE>
<FONT COLOR="#000000">Recently quite a few individuals have attempted to break 
into a server I </FONT>
<FONT COLOR="#000000">manage through a recently-found vulnerability in phpBB. 
Here's what each </FONT>
<FONT COLOR="#000000">of them attempted:</FONT>
</PRE>
</BLOCKQUOTE>
<BR>
<BLOCKQUOTE TYPE=CITE>
<PRE>
<FONT COLOR="#000000">Attachker #2: Downloading some kind of bot to our /tmp 
(using wget). For </FONT>
<FONT COLOR="#000000">some strange reason, he hasn't continued the 
breakin.</FONT>
</PRE>
</BLOCKQUOTE>
<BR>
For that I put /tmp mounted as noexec (maybe you did too and that's why he 
didn't continue? :))<BR>
<BR>
Plus, just don't put any apache-writable place on the whole system. As for the 
logs, put them on a different filesystem, and again, mount it noexec. &quot;If 
they can't execute their stuff...&quot;.<BR>
<BR>
Of course it's possible to do the above mentioned stuff with other security 
capabilities, but the concept is what's important.<BR>
<BR>
Oh, and by the way... DON'T USE PHPBB :)<BR>
<BR>
<TABLE CELLSPACING="0" CELLPADDING="0" WIDTH="100%">
<TR>
<TD>
-- <BR>
shimi &lt;<A HREF="mailto:[EMAIL PROTECTED]">[EMAIL PROTECTED]</A>&gt;
</TD>
</TR>
</TABLE>
</BODY>
</HTML>

--=-qdRMs+J0zjXW/jcU/00T--


=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]

Reply via email to