View Single Post

  #2 (permalink)  
Old 06-25-2007, 09:57 PM
monk's Avatar
monk monk is offline
Senior Member
User
 
Join Date: Jan 2005
Location: Tibet
My distro: Debian GNU/Linux
Posts: 482
Rep Power: 5
monk will become famous soon enough monk will become famous soon enough
Default

The best way to avoid /tmp upload is mount tmp on its own partition and setup noexec mount flag. Also make sure you run susexe for PHP.

Ultimate solution is install mod_security for Apache and chroot jail (it may not not work with CP such as Plesk)

Hope this helps
__________________
May the force with you!
Reply With Quote