security question

Arie Kachler akachler at telcom.net
Wed Aug 15 10:25:47 PDT 2007


Hello,

This may not be the best place to ask, but I know all readers of this 
list have security experience (we have no other choice).

We have many Freebsd servers with apache/php/mysql.
Recently, some of these have been sending out large amounts of emails. 
We know the servers are secure in the sense they are fully patched. But 
we also know that the most secure shared server can be abused by a badly 
written php script.

So my question is this:
Is there a way to identify vulenrable php scripts?
It's very difficult to pinpoint when the server starts sending out 
emails. We just notice that they do, without any identifyable 
correlation to anything on the logs.

A related question:
Can we audit which php script is calling sendmail?

Any advice will be greatly appreciated.

Arie Kachler
Systems Administrator
Telcom.Net





More information about the freebsd-isp mailing list