[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Linux: /tmp noexec - useful or not?

Posted on 2013-01-26
3
Medium Priority
?
649 Views
Last Modified: 2013-02-15
Hi,

Is there any benefit by mounting /tmp with noexec?
I've heard that even with that, there are workarounds to execute scripts in /tmp.

Is that true? If so, how is this possible?

Thank you
0
Comment
Question by:g0all
3 Comments
 
LVL 20

Assisted Solution

by:edster9999
edster9999 earned 1000 total points
ID: 38822107
Its worth doing.
You should also set nodev and nosuid if possible.

Why would you do this ? Most vlaid users, whether they are a real user (like a person with an account on the machine) or a user that allows a process to run (like the user your webserver runs as) would have the ability to drop files into this folder and change things in there.  They can then cause it to be run either by themselves or by someone with more rights than them.
Adding these locks stop the commands being run so easily.  You have to use another step to get them to run.
Think of this as locking your house door.  You are saying you have heard there are other ways to get into a house so should you lock your doors.
Yes - of course you should, it may slow down or stop a script-kid from gaining root access to your server :)

How can people still run things ? Well there are at least a couple of different ways.
One of them involves not running it, but passing it as a parameter into another program (for example the bash shell).  Another way involves an older exploit using /lib/ld-linux.so to execute the code - but this has been patched on most Linuxes now.
No matter how much you patch - there will always still be holes that can be exploited. The best thing to do is patch and lock as many as are known.

Good luck
0
 
LVL 4

Expert Comment

by:ReN501
ID: 38829337
put simply , do it , /tmp is one of the very few folders or partitions ( default ) that has global read/write/execute access , by not allowing execute access this will prevent alot script kiddie attempts to run scripts etc, especially if your running a web server.
0
 
LVL 62

Accepted Solution

by:
gheist earned 1000 total points
ID: 38853130
Yes - script interpreter like BASH or PERL will run any file passed as parameter to them, even if otherwise execve (you know that #!/bin/init 0 in front of file) would not work...
0

Featured Post

Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Virtualization software lets you run different versions of Windows, Ubuntu Linux and other versions of Linux all at the same time, rather than running each one directly from your computer's hard drive.
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Suggested Courses
Course of the Month9 days, 11 hours left to enroll

591 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question