Re: [SLUG] mounting /tmp non executable ?

2006-12-26 Thread Penedo
On 19/12/06, Alex Samad <[EMAIL PROTECTED]> wrote: On Tue, Dec 19, 2006 at 08:26:52AM +1100, Voytek Eymont wrote: > on several ocassions I had malware downloaded and executed from /tmp > (through CMS vulnerability); > > there was a suggestion here to mount /tmp as non executable; > > - do I need

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Scott Ragen
[EMAIL PROTECTED] wrote on 21/12/2006 12:56:42 PM: > > On Thu, December 21, 2006 11:47 am, [EMAIL PROTECTED] wrote: > > > > > Why not make /tmp a tmpfs partition? If your machine has plenty of > > RAM and swap, it's faster still. And /tmp/* is deleted on each boot > > so there's no real reason

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Voytek Eymont
On Thu, December 21, 2006 11:47 am, [EMAIL PROTECTED] wrote: > > Why not make /tmp a tmpfs partition? If your machine has plenty of > RAM and swap, it's faster still. And /tmp/* is deleted on each boot > so there's no real reason for it to be permanent storage. I have 2GB, how much would you s

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Sridhar Dhanapalan
On Thursday 21 December 2006 01:01, Sridhar Dhanapalan <[EMAIL PROTECTED]> wrote: > To those options, I would add 'noatime,nodiratime,noexec'. The first two > give you a tiny bit more speed by not maintaining access times on files > (probably unnecessary on /tmp) To clarify, I meant that maintain

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread peter
Why not make /tmp a tmpfs partition? If your machine has plenty of RAM and swap, it's faster still. And /tmp/* is deleted on each boot so there's no real reason for it to be permanent storage. -- Dr Peter Chubb http://www.gelato.unsw.edu.au peterc AT gelato.unsw.edu.au http://www.ertos.nicta.

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Sridhar Dhanapalan
On Wednesday 20 December 2006 23:59, "Voytek Eymont" <[EMAIL PROTECTED]> wrote: > On Wed, December 20, 2006 11:38 pm, Voytek Eymont wrote: > > On Wed, December 20, 2006 11:10 pm, Alexander Stanley wrote: > >> Sridhar Dhanapalan wrote: > >>> On Tuesday 19 December 2006 08:26, "Voytek Eymont" <[EMAIL

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Voytek Eymont
On Wed, December 20, 2006 11:38 pm, Voytek Eymont wrote: > > On Wed, December 20, 2006 11:10 pm, Alexander Stanley wrote: >> Sridhar Dhanapalan wrote: >> >>> On Tuesday 19 December 2006 08:26, "Voytek Eymont" <[EMAIL PROTECTED]> >>> > >>> I've been doing this for a number of years. Generally it i

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Sridhar Dhanapalan
On Wednesday 20 December 2006 23:38, "Voytek Eymont" <[EMAIL PROTECTED]> wrote: > On Wed, December 20, 2006 11:10 pm, Alexander Stanley wrote: > > Sridhar Dhanapalan wrote: > >> On Tuesday 19 December 2006 08:26, "Voytek Eymont" <[EMAIL PROTECTED]> > >> > >> I've been doing this for a number of yea

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Voytek Eymont
On Wed, December 20, 2006 11:10 pm, Alexander Stanley wrote: > Sridhar Dhanapalan wrote: >> On Tuesday 19 December 2006 08:26, "Voytek Eymont" <[EMAIL PROTECTED]> >> I've been doing this for a number of years. Generally it is a good >> idea. thanks, Sridhar, Alexander so, do I edit /etc/mtab ?

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Alexander Stanley
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Sridhar Dhanapalan wrote: > On Tuesday 19 December 2006 08:26, "Voytek Eymont" <[EMAIL PROTECTED]> wrote: >> on several ocassions I had malware downloaded and executed from /tmp >> (through CMS vulnerability); >> >> there was a suggestion here to mount

Re: [SLUG] mounting /tmp non executable ?

2006-12-20 Thread Sridhar Dhanapalan
On Tuesday 19 December 2006 08:26, "Voytek Eymont" <[EMAIL PROTECTED]> wrote: > on several ocassions I had malware downloaded and executed from /tmp > (through CMS vulnerability); > > there was a suggestion here to mount /tmp as non executable; > > - do I need to partition the HD and make a separat

Re: [SLUG] mounting /tmp non executable ?

2006-12-18 Thread Alex Samad
On Tue, Dec 19, 2006 at 08:26:52AM +1100, Voytek Eymont wrote: > on several ocassions I had malware downloaded and executed from /tmp > (through CMS vulnerability); > > there was a suggestion here to mount /tmp as non executable; > > - do I need to partition the HD and make a separate partition f

[SLUG] mounting /tmp non executable ?

2006-12-18 Thread Voytek Eymont
on several ocassions I had malware downloaded and executed from /tmp (through CMS vulnerability); there was a suggestion here to mount /tmp as non executable; - do I need to partition the HD and make a separate partition for /tmp? - good/bad/excellent idea ? -- Voytek -- SLUG - Sydney Linux U