[geeks] Compilers - safe on servers?

Mark Benson md.benson at gmail.com
Mon Mar 2 08:43:21 CST 2009


der Mouse wrote:
> This is true as far as it goes, but there are so many ways to get a
> binary compiled elsewhere onto the machine that it doesn't make much
> difference in practice.
> 
> Unless, of course, you have it locked down so tight during normal
> operation that there _aren't_ a zillion different ways to get a binary
> from elsewhere onto it, in which case you have a valid point.

Well for one thing i notice Curl and WGet are both abscent. That's one 
channel out of the window. I am currently dropping stuff to thwe server 
via SFTP from my workstaion.

> What I would probably do is to go ahead and install the compiler, then
> uninstall it when I'm done using it.  I might even install the compiler
> on an external drive which I then remove for production use.

Sounds like a sensible couple of ideas. If I had the path to gcc set to 
something that didn't exist I guess all it'd do is fall over when anyone 
tried to compile... whichj is good :)

Thanks :)

-- 

Mark Benson
http://markbenson.org/blog
http://twitter.com/MDBenson
http://flickr.com/photos/pixel_mason



More information about the geeks mailing list