Full Disclosure mailing list archives

Re: Re: January 15 is Personal Firewall Day, help the cause


From: Martin Mačok <martin.macok () underground cz>
Date: Mon, 19 Jan 2004 00:41:36 +0100

On Sun, Jan 18, 2004 at 10:14:48AM -0500, David F. Skoll wrote:

Mounting /tmp noexec also protects against future threats, not just
ones that happen to be in the AV database.

(I know that someone recently released code to do a "user-space"
exec, so mounting /tmp noexec is not 100% foolproof, but it's pretty
good protection.)

Easy one. Execute "/lib/ld-linux.so.2 /tmp/code".

-- 
         Martin Mačok                 http://underground.cz/
   martin.macok () underground cz        http://Xtrmntr.org/ORBman/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: