hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : /tmp chmod setting
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

/tmp chmod setting

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 06-28-2006, 09:03 PM
jethbrown jethbrown is offline
Junior Guru Wannabe
 
Join Date: Nov 2004
Location: Edmonton, Alberta
Posts: 90

/tmp chmod setting


What setting should this be? I had it 1777 and I was getting the eggdrop problem in it, I made it 0755 and it secured it, but to well. Now phpmyadmin won't work, I put it back to 1777 or 0777 and phpmyadmin works just fine. I have it noexec and on another partition as suggested in many places in the forums.

__________________
Jim Brown, BSc
Alberta Internet Host Providers Ltd.


Reply With Quote


Sponsored Links
  #2  
Old 06-28-2006, 09:30 PM
eth00 eth00 is offline
Web Hosting Master
 
Join Date: Apr 2003
Location: NC
Posts: 2,911
0777 or 0755 will not help prevent and eggdrop from running. What will stop an eggdrop is the noexec. Go ahead and set it to chmod 0777 and it will be fine. The only thing you have to watch for is perl scripts getting uploaded and run which tends to happen frequently if your server is not hardened against such attacks.

__________________
John W
www.eth0.us

Reply With Quote
  #3  
Old 06-29-2006, 04:39 AM
Bilco105 Bilco105 is offline
Web Hosting Master
 
Join Date: Oct 2002
Location: Manchester, UK
Posts: 1,164
Make sure /tmp is mounted noexec, nosuid.

__________________
Rob Greenwood
RedHat Certified, Unix Consultant
http://www.linkedin.com/in/bilco105

Reply With Quote
Sponsored Links
  #4  
Old 06-29-2006, 09:51 AM
pmabraham pmabraham is offline
Web Hosting Master
 
Join Date: Dec 2001
Posts: 5,221
Greetings:

chmod 0777 /tmp
chmod +t /tmp

Plus securing /tmp

Please note that /tmp security ** does not ** mean that hackers will not be able to use /tmp for their own benefit. That's why multiple layers of security such as securing your compilers, fetch like programs, using mod_security, and other layers matter so much.

Thank you.

__________________
---
Peter M. Abraham
LinkedIn Profile


Reply With Quote
  #5  
Old 06-29-2006, 11:00 AM
Ramprage Ramprage is offline
Keep rockin' in the free world
 
Join Date: May 2002
Location: Kingston, Ontario
Posts: 1,548
Sometimes it's not just /tmp that's the issue, an attacker will find an exploitable script in a users directory and upload files to it. Nobody Check can help find malicious processes running appearing to be something else, eg: Apache, Sendmail or other daemons.

__________________
Upload Guardian 2 - AntiMalware Protection - Windows and Linux!
PHP encoded protection, real-time scans
Get notified when released

Reply With Quote
  #6  
Old 06-30-2006, 01:28 PM
gbjbaanb gbjbaanb is offline
Retired Moderator
 
Join Date: Oct 2004
Location: Southwest UK
Posts: 1,159
why does NobodyCheck require cpanel?

Please bear in mind that some processes, eg. logrotate, will break if you secure your /tmp, so you'll need to specify a differnet temp directory for them to use.

Reply With Quote
  #7  
Old 06-30-2006, 07:58 PM
jethbrown jethbrown is offline
Junior Guru Wannabe
 
Join Date: Nov 2004
Location: Edmonton, Alberta
Posts: 90
Thanks everyone, I hired a security expert from here to secure my server and migrate it's os to a more current release.

__________________
Jim Brown, BSc
Alberta Internet Host Providers Ltd.


Reply With Quote
  #8  
Old 07-10-2006, 10:57 AM
Ramprage Ramprage is offline
Keep rockin' in the free world
 
Join Date: May 2002
Location: Kingston, Ontario
Posts: 1,548
Quote:
Originally Posted by gbjbaanb
why does NobodyCheck require cpanel?
Its currently being made to support Plesk and DirectAdmin for the next release.

__________________
Upload Guardian 2 - AntiMalware Protection - Windows and Linux!
PHP encoded protection, real-time scans
Get notified when released

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Inerol Solutions Launches XEN VPS Hosting Service Web Hosting News 2013-04-08 12:32:06
50c620da-e6f0-4724-9d7f-2ccc45a79943 Listing 2013-03-05 18:23:14
Web Host Rackspace Adds FreeBSD 9, CentOS 6.3 Support to Cloud Servers Web Hosting News 2012-07-30 12:47:10
Email Provider Atmail Releases One-Click iOS Provisioning with Atmail 6.3 Web Hosting News 2011-11-28 20:34:19
Q&A: Liquid Web's Cale Sauter Discusses the Web Host's New CDN Service Web Hosting News 2011-05-25 14:40:01


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?