mod_security FTW
The other night, I noticed that popsicle.easymac.org’s mailq was >22,000 message. I figured that was a problem. Turns out one of my users (who’s account I deleted without hesitation) was running a PHP proxy from his ~ directory. Looks like the stupid thing allowed some idiot to download some obnoxious looking perl scripts into the /tmp directory, and execute them repeatedly, while making periodic connections to an IRC server hosted at theplanet’s shitty facilities (which I hope have the chance to explode… again).
Anyway, somebody who I take very seriously told me, very seriously, that I should consider mod_security. So I did. It’s awesome. I’ll never look back.