RE: [EMAIL PROTECTED] HTTPD 2.2.3 possible exploit?

2007-07-02 Thread Chris Robertson
> >Chris Robertson wrote: >> >> Where's the posix api and dl-functionality report? Any specific >> keywords to narrow it down? > >disable_*** in php.ini? I thought you meant a vulnerability/exploit report... >> I actually started with PHP as my most l

RE: [EMAIL PROTECTED] HTTPD 2.2.3 possible exploit?

2007-07-02 Thread Chris Robertson
>nothing else you mention even raises an eyebrow. These two are likely >your culprits if you run untrusted scripts. I'd disable all the posix >api functions and dl-functionality based on a recent report. > >As far as /root/2/ that doesn't correspond to something I know of, but >limiting users who

[EMAIL PROTECTED] HTTPD 2.2.3 possible exploit?

2007-07-02 Thread Chris Robertson
Over the weekend we had several servers that all experienced the same symptoms (details below). I've gone through the CVE, bugtraq, etc archives and haven't found anything that matches either our versions or the symptoms. Symptoms: - Server exhibits small jump in number of processes in queue and