[Security-Discuss] apache exploit?

Jason M Temple <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Hello,

We are running mandrake official 10.1, with all the latest updates, as a web server.

Apache is at apache2-common-2.0.50-7.2.101mdk.

We were recently nailed by a cracker called ImFlower, who somehow managed to get in using the apache user, and was running elflbl to try and get root perms.  Is the apache level above patched for all the recent exploits that were patched in the apache.org 2.0.52 release?

Any help on this would be appreciated.

Thanks,

Jason
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.