Help - Search - Members - Calendar
Full Version: /tmp Hack - Help?
The Planet Forums > Security > General Security > UNIX Security
Cham911
Hey everyone,

Sorry for the noob question. I seem to have someone using Apache to put perl scripts in my /tmp directory. I've made the tmp noexec as of a coupel days ago, but would really like to find the offending script, or place where they are exploiting.

Any suggestions on where to start, would be helpful.

Thank you
dynamicnet
Greetings:

The hardening of tmp can be bypassed.

I do recommend checking the Apache logs (access / transfer) to see if you are hosting a particular site that has insecure perl/CGI or PHP code allowing such uploads.

Thank you.
GatorZach
Little trick I used to do is to replace /usr/local/bin/perl with a script that logged to a file instead of executing perl code.
You might want to look at perlsec too.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.