Re: /tmp noexec?


To Debian CZ/SK project discussion list <czdebian-l zavinac debian bod cz>
From Jan Korbel <debian zavinac teptin bod net>
Date Sat, 03 Mar 2007 21:52:01 +0100
User-agent Icedove 1.5.0.9 (X11/20061220)

O neco lepsi reseni je /etc/apt/apt.conf.d/51tmp:

DPkg::Pre-Invoke {"mount -o remount,exec /tmp";};
DPkg::Post-Invoke {"mount -o remount /tmp";};

Jestli je to zaklad nevim, da se to lehce obejit (/bin/sh /tmp/neco.sh). Ale cim odlisnejsi budou nase servery, tim vice sanci mame proti script kiddies :)

H.

Miroslav Zajíc wrote:
  Zdravim,
pouzivam to tez uz delsi dobu, a z tohoto duvodu mam tento alias:
alias 'aptduu'='mount /tmp/ -o remount,exec ; apt-get update ; apt-get dist-upgrade ; mount /tmp/ -o remount,noexec'

Nicmene, neni to zcela ono, nefunguje kvuli tomu napr. komprimace v MC (pres F2) a tak dale... Optimalni reseni bude neco jako GR Security, ci tak neco, ale k tomu sem se jeste nedokopal...

Zajsoft



Partial thread listing: