Talking of SSP, what can you do once a detection happens? I see in /var/log/messages:
Nov 15 06:59:32 mail -: mail.example.com exim - - - stack overflow detected; terminated I have: kern.coredump.setid.dump = 1 kern.coredump.setid.path = /var/crash/%n.core proc.curproc.rlimit.coredumpsize.soft = unlimited proc.curproc.rlimit.coredumpsize.hard = unlimited but /var/crash is empty. How do you make use of SSP? Cheers, Patrick
