linux-admin.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Making directories non-executable?
@ 2004-03-23 18:25 Jens Knoell
  2004-03-23 20:16 ` Glynn Clements
  2004-03-23 22:37 ` Nico Schottelius
  0 siblings, 2 replies; 6+ messages in thread
From: Jens Knoell @ 2004-03-23 18:25 UTC (permalink / raw)
  To: Linux Admin

In an effort to tighten security, I'm trying to find out if there is any 
solution out there to make certain world-writable directories non-executable? 
I'd imagine an execve() wrapper should be able to do that, but I was not 
graced with finding any solution at all.

Jen

^ permalink raw reply	[flat|nested] 6+ messages in thread
* Re: Making directories non-executable?
@ 2004-03-24  6:47 George  Iosif
  0 siblings, 0 replies; 6+ messages in thread
From: George  Iosif @ 2004-03-24  6:47 UTC (permalink / raw)
  To: jens; +Cc: linux-admin

There is an option when mounting partitions: noexec .
It is advisable to have a separate partition for /tmp (if this is the
directory you're trying to make it a "non executable medium") and mount
it with noexec (and nosuid) option(s).



George Iosif


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2004-03-24 12:30 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-23 18:25 Making directories non-executable? Jens Knoell
2004-03-23 20:16 ` Glynn Clements
2004-03-23 22:20   ` Jens Knoell
2004-03-24 12:30     ` Glynn Clements
2004-03-23 22:37 ` Nico Schottelius
  -- strict thread matches above, loose matches on Subject: below --
2004-03-24  6:47 George  Iosif

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).