Full Disclosure mailing list archives
Re: Re: New Santy-Worm attacks *all* PHP-skripts
From: Steve Wray <steve () myself gen nz>
Date: Mon, 27 Dec 2004 09:32:00 +1300
Paul Laudanski wrote:
On Sat, 25 Dec 2004, Raistlin wrote:Juergen Schmidt wrote:Hello, the new santy version not only attacks phpBB.How would these two worms react to classical hardening tips such as PHP Safe mode and noexec /tmp ?For this particular strain it would certainly help, but that is why there exists new variations. Certainly doing it to /tmp, /usr/tmp, /var/tmp could help, but it isn't 100% foolproof, and some don't even consider it security.
It only protects you from exploits that cannot just go; source /tmp/rootkit.sh or other, equivalent methods.ie its only effective against directly executing files on those filesystems; you can still use other methods to run them.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Re: New Santy-Worm attacks *all* PHP-skripts Paul Laudanski (Dec 26)
- <Possible follow-ups>
- New Santy-Worm attacks *all* PHP-skripts Gary E. Miller (Dec 26)
- New Santy-Worm attacks *all* PHP-skripts Juergen Schmidt (Dec 29)
- Re: New Santy-Worm attacks *all* PHP-skripts Paul Laudanski (Dec 25)
- Re: New Santy-Worm attacks *all* PHP-skripts Paul Laudanski (Dec 27)
- Re: New Santy-Worm attacks *all* PHP-skripts Raistlin (Dec 26)
- Re: Re: New Santy-Worm attacks *all* PHP-skripts Paul Laudanski (Dec 26)
- Re: Re: New Santy-Worm attacks *all* PHP-skripts Steve Wray (Dec 29)
- Re: New Santy-Worm attacks *all* PHP-skripts Paul Laudanski (Dec 25)
- Re: New Santy-Worm attacks *all* PHP-skripts Pekka Savola (Dec 29)
- Re: New Santy-Worm attacks *all* PHP-skripts Juergen Schmidt (Dec 29)