www/160247: Website vulnerability
Glen Barber
gjb at FreeBSD.org
Sat Sep 3 23:48:27 UTC 2011
On 9/3/11 4:29 PM, Alvaro Castillo wrote:
> On Sun, Aug 28, 2011 at 2:20 AM, Glen Barber <gjb at freebsd.org> wrote:
>> On 8/27/11 9:02 PM, Alvaro wrote:
>>>> Description:
>>> The problem is on mod_deflate.
>>>
>>
>> No it isn't.
>>
>> http://seclists.org/fulldisclosure/2011/Aug/236
>>
>
> The problem has been fixed on Apache 2* but Apache 13 isn't maintained
> by Apache Foundation.
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192
>
> Sorry but mod_deflate was included... need to disable it and set Range
> Pequest and so on
>
> http://translate.google.es/translate?hl=es&sl=es&tl=en&u=http%3A%2F%2Fwww.securityartwork.es%2F2011%2F08%2F25%2Fdenegacion-de-servicio-en-apache%2F
>
> Not yet solved...
> > perl killapache.pl www.freebsd.org
> host seems vuln
> ATTACKING www.freebsd.org [using 50 forks]
> ^C
>
Sorry, but www.freebsd.org does not use Apache.
--
Glen Barber | gjb at FreeBSD.org
FreeBSD Documentation Project
More information about the freebsd-www
mailing list