[grsec] TPE - Apache want to run a picture ?

azurIt azurit at pobox.sk
Thu May 5 17:30:21 EDT 2005


hi guys,

i have the same problem on several machines but i was ignoring it :) 
apache is trying to run images, html files, etc. when someone is 
requesting then (when is viewing the web page). permissions on files 
are -x :)

grsec: From 84.47.78.12: denied executable mmap 
of /mnt/hdd5/webmaster/www/prijimacky.html by /usr/sbin/httpd
[httpd:20862] uid/euid:99/99 gid/egid:98/98, parent /usr/sbin/httpd
[httpd:15370] uid/euid:0/0 gid/egid:0/0

root at eniac:~# ls -la /mnt/hdd5/webmaster/www/prijimacky.html
-rw-r--r--    1 webmaster users       96446 May  5 
19:55 /mnt/hdd5/webmaster/www/prijimacky.html


azurIt

> > > After turning on TPE, I received a lot of messages like:
> > 
> > Looks like it's trying to map the image files executable (which 
is 
> > wrong).  Just to be sure, can you mail me an
> > strace -e open,old_mmap,mprotect of the apache process?
> 
> add mmap2 to the list, your glibc might (even should ;-) be using
> that instead of old_mmap. also, what are the unix file permissions 
on
> the image files?
> 
> _______________________________________________
> grsecurity mailing list
> grsecurity at grsecurity.net
> http://grsecurity.net/cgi-bin/mailman/listinfo/grsecurity
> 

____________________________________
Vsetko o SuperStar
http://superstar.atlas.sk



More information about the grsecurity mailing list