exec in /tmp

anyone here runs a script that deletes all files in tmp that do not match specific name mask?

I am thinking of putting something there that would remove everything that should not be in /tmp every 20 seconds or so. Only, or at least the most probable way for someone to get in the server, is broken script somewhere, then chances ar that getting in will involve dropping and/or compiling some stuff in /tmp. I know that idealy tmp would be partition with noexec but that is not the case here. Comments welcome.

 

 

 

 

Top