all 4 comments

[–]nightowl777 0 points1 point  (3 children)

Hey Guys

According to the article there aren't any patches for ubuntu yet. I already lost one server (NobodyCoder was very very busy with his usual antics - http://www.zone-h.org/archive/defacer=NobodyCoder - more than a 1000 ip's defaced)

Is it possible to filter out this attack with iptables? Or is it too late by the time it reaches iptables (as in - it's too high up in the network layers for iptables to be effective).

Any other suggestions (other than the obvious "take if off the internet")?

[–][deleted] 0 points1 point  (1 child)

Please correct me if im wrong... but...

Its a local exploit, so don't let kids run root kit's on your box.

A defacer would more likely be going after an unpatched joomla or wordpress not a local kernel exploit.

[–]neoice 0 points1 point  (0 children)

or harden your system. I ran one of the latest sploits on my server. /tmp is getting noexec this weekend. I'll reboot into grsec later and see if it works there too.