I have seen multiple script kiddies try to hide stuff in /dev/shm due to it generally being available and allowing executables.  No exec is a good idea, though I would test any important apps before doing production that way.

On a side note, the best deterrent I have found for script kiddies was to lock down outbound connections to only specifically what you need.  If they cannot connect out, the server becomes a lot less desirable.  Of course, keeping them out in the first place is best, but you cannot always control that with other users that can run whatever they want to.


