    Very nice stuff is published here


    Basically it means the attacker can upload any source code to your web site and execute it using LD_PRELOAD when normal exec calling. Means you can see, f.ex. host command running, but instead of host you are joining the bot net.
    As we run php from suexec daemon, do you know if there is any way to disable LD_PRELOAD at all?
    Not much can be done in user land, maybe patched kernel can help.
    If you want to make the hacker a little difficult to exploit it, disable exec() in PHP.

