Beefy Boxes and Bandwidth Generously Provided by pair Networks
Perl-Sensitive Sunglasses

Re: Possible intrusion?

by kikuchiyo (Monk)
on Jun 11, 2010 at 11:05 UTC ( #844210=note: print w/replies, xml ) Need Help??

in reply to Possible intrusion?

An idea: why don't you mount /tmp with a noexec flag, so that they can't run anything from it even if they uploaded their malicious code? (For this, /tmp has to be on a separate partition.)

Replies are listed 'Best First'.
Re^2: Possible intrusion?
by choroba (Chancellor) on Jun 11, 2010 at 12:24 UTC
    Better than nothing, but it would still be possible to run the script by perl /tmp/