Re: Debian Stable server hacked

2003-08-14 Thread valerian
On Wed, Aug 13, 2003 at 07:08:59PM -0400, Colin Walters wrote: But Linux capabilities are so weak. They won't protect an apache master process that runs as root from scribbling over /etc/passwd and giving an attacker a new uid 0 shell account, for example. At that point it's really game

Re: Debian Stable server hacked

2003-08-14 Thread valerian
On Wed, Aug 13, 2003 at 04:02:41PM -0400, Colin Walters wrote: Why? Because SELinux doesn't solely associate security with executable pathnames. If someone takes over control of the apache process via a buffer overflow or whatever, they don't need /bin/ls to list a directory; they can just as

Re: Debian Stable server hacked

2003-08-13 Thread valerian
On Wed, Aug 13, 2003 at 04:02:41PM -0400, Colin Walters wrote: Why? Because SELinux doesn't solely associate security with executable pathnames. If someone takes over control of the apache process via a buffer overflow or whatever, they don't need /bin/ls to list a directory; they can just as

Re: Debian Stable server hacked

2003-08-13 Thread valerian
On Wed, Aug 13, 2003 at 07:08:59PM -0400, Colin Walters wrote: But Linux capabilities are so weak. They won't protect an apache master process that runs as root from scribbling over /etc/passwd and giving an attacker a new uid 0 shell account, for example. At that point it's really game

Re: Strongest linux

2003-07-01 Thread valerian
On Tue, Jul 01, 2003 at 02:36:37PM +0200, Javier Castillo Alcibar wrote: Hi all, I want to setup a new linux server in internet (apache, php, postfix, mysql, dns...), and I would like to patch the standard kernel with some security patches. but my question is, what patches are the best??

Re: Strongest linux

2003-07-01 Thread valerian
On Tue, Jul 01, 2003 at 02:36:37PM +0200, Javier Castillo Alcibar wrote: Hi all, I want to setup a new linux server in internet (apache, php, postfix, mysql, dns...), and I would like to patch the standard kernel with some security patches. but my question is, what patches are the best??

Re: Fwd: bugtraq.c httpd apache ssl attack

2002-09-14 Thread valerian
On Sat, Sep 14, 2002 at 12:56:00PM +0200, Wichert Akkerman wrote: One wonders why you would have gcc installed on a webserver.. Look at places like he.net... They offer full unix environment hosting services (including gcc).