Re: help in patching
peredina <[email protected]> Wed, 26 Jun 2002 07:34:00 -0400
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
I dont work for eEye, but from my tests, I can say that is NOT true. I have tested the tool with patched, and unpatched versions of 1.3.20 (setting both generic banners and default banners), and it does not appear to be looking at the banners. In all my tests, the vulnerability scan picked up the correct information regarding the fix. Im not telling anyone they shouldnt upgrade, Im just letting you know what I've found out about the eEye tool personally....I've already upgraded what I've had to. Thanks, Curt Mark J Cox wrote: >>Did you actually verify that this release is vulnerable to the chunk >>enconding problem? I have a Stronghold 3 release that WAS NO vulnerable. > > > All Apache releases since Apache 1.2 are vulnerable to the chunked > encoding issue, therefore so are all releases of Stronghold. We have been > informed that the eEye tool was looking only at the returned server > version to make its assesment of vulnerability, however that is not > sufficient to find Stronghold (which changes the server version string), > or servers that are not running Apache 1.3.26 but have been patched. > > [Although all releases of Stronghold are vulnerable the effects and > exploitability vary from platform to platform. We suggest that all > Stronghold users apply the patch or upgrade to the 3017 binaries] > > Cheers, Mark > -- > Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation > [email protected] // T: +44 798 061 3110 // F: +44 870 1319174 > > > > > _______________________________________________ > Stronghold-users mailing list > [email protected] > https://listman.redhat.com/mailman/listinfo/stronghold-users