Re: [Security-Discuss] Apache2 mod_proxy and 9.2(.1)

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Aug 10, 2004, at 7:56 AM, bob-6dd4Sf22++lWk0Htik3J/[email protected] wrote:

> Hello People,
>
> Here is what appears to me to be another real problem.
>
> In -all- of my 9.2 or 9.2.1 boxes that have apache2 installed, 
> mod_proxy
> is enabled.  I never specifically enabled this.  I only discovered it
> when one of my boxes (on a RR line) started generating huge amounts of
> traffic, as a spammer had found the proxy, and was using it to do his
> dirty work.
>
> If the default install of Apache2 isn't enabling this, then there must
> be some other RPM that is.  Any ideas?

The apache2-mod_proxy rpm?

You have it installed which means, as far as the system is concerned, 
you want it enabled.  I don't particularly agree with that methodology, 
but that's what we have.  Ie. if you install a service, such as postfix 
or ucd-snmp or something, you must want it starting right away, and 
it's enabled.  I believe the same is true with apache modules.

For apache modules, php modules, etc. I'm a little more forgiving.  If 
you have it installed, you likely do want to use it.  It's a little 
different than "install service xyz, start xyz by default", which 
really irks me.

Either comment it out or remove the apache2-mod_proxy rpm.  At some 
point you installed it.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FE6F2AFD : 88D8 0D23 8D4B 3407 5BD7  66F9 2043 D0E5 FE6F 2AFD}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.