Hi,based on mod_ssl HOWTOs and documentations I believed that mod_ssl makes use
of the openSSL engine in /usr/sbin/. Therefore I compiled the new version for this. Am I save now? - GerritOn Montag, Sep 16, 2002, at 11:16 Europe/Berlin, Wouter van Reeven wrote:
Hi, there is a temporary solution for this worm : run chmod 700 /usr/bin/gccas root. The worm needs to be able to compile in order to execute. Disabling the execution permissions for the httpd user will prevent this, therefore prevent the worm from executing. It's nothing permanent of course, since no one will be able to compile apart from root...Wouter van Reeven