Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 2 Jul 2002 12:26:16 -0400 (EDT)
From:      David Miller <dmiller@sparks.net>
To:        Andy Farkas <andyf@speednet.com.au>
Cc:        Kent Stewart <kstewart@owt.com>, security@FreeBSD.ORG
Subject:   Re: FreeBSD.Scalper.Worm
Message-ID:  <Pine.BSF.4.21.0207021225080.81781-100000@search.sparks.net>
In-Reply-To: <Pine.BSF.4.33.0206302244150.42445-100000@backup.af.speednet.com.au>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 30 Jun 2002, Andy Farkas wrote:

> On Sat, 29 Jun 2002, Kent Stewart wrote:
> 
> > One of the people sending mail to -docs, pointed me to
> >
> > http://securityresponse.symantec.com/avcenter/venc/data/freebsd.scalper.worm.html
> >
> > It looks like more exposure needs to be provided via the web site and etc.
> >
> > Kent
> >
> > --
> > Kent Stewart
> > Richland, WA
> >
> > http://users.owt.com/kstewart/index.html
> >
> 
> Looks like this worm can be stopped by having /tmp mounted noexec.

Probably not a very good solution since it could be overcome with a
trivial change to the worm.  The better fix is to plug the hole:)

--- David


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0207021225080.81781-100000>