Possible Apache vulnerability
Billy O'Connor <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Linux From Scratch |
| Message-ID | <[email protected]> |
This affect the TRACE command. I'm still looking into it. http://www.extremetech.com/article2/0,3973,841144,00.asp http://www.whitehatsec.com/press_releases/WH-PR-20030120.txt QUOTE: After discovering the vulnerability, WhiteHat attempted to find a way to mitigate the issue on web servers but found that no web servers had the ability to disable the TRACE command. WhiteHat found a way to work around these oversights but some are not supported by the vendors. -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message