Re: [Security-Discuss] Apache2 mod_proxy and 9.2(.1)

"Bob Puff@NLE" <bob-6dd4Sf22++lWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Hi Vince,

Thanks for the reply.  It must have been auto-selected when Apache was selected in the package
list, because I don't recall specifically enabling it.

Still, even if enabled, shouldn't it be configured _not_ to proxy from the outside by default, like 
squid?

Bob

Vincent Danen wrote:
> 
> On Aug 10, 2004, at 7:56 AM, bob-6dd4Sf22++lWk0Htik3J/[email protected] wrote:
> 
>> Hello People,
>>
>> Here is what appears to me to be another real problem.
>>
>> In -all- of my 9.2 or 9.2.1 boxes that have apache2 installed, mod_proxy
>> is enabled.  I never specifically enabled this.  I only discovered it
>> when one of my boxes (on a RR line) started generating huge amounts of
>> traffic, as a spammer had found the proxy, and was using it to do his
>> dirty work.
>>
>> If the default install of Apache2 isn't enabling this, then there must
>> be some other RPM that is.  Any ideas?
> 
> 
> The apache2-mod_proxy rpm?
> 
> You have it installed which means, as far as the system is concerned, 
> you want it enabled.  I don't particularly agree with that methodology, 
> but that's what we have.  Ie. if you install a service, such as postfix 
> or ucd-snmp or something, you must want it starting right away, and it's 
> enabled.  I believe the same is true with apache modules.
> 
> For apache modules, php modules, etc. I'm a little more forgiving.  If 
> you have it installed, you likely do want to use it.  It's a little 
> different than "install service xyz, start xyz by default", which really 
> irks me.
> 
> Either comment it out or remove the apache2-mod_proxy rpm.  At some 
> point you installed it.
>
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.