Re: help in patching

Mark J Cox <[email protected]> Wed, 26 Jun 2002 12:44:27 +0100 (BST)
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
> I have tested the tool with patched, and unpatched versions of 1.3.20 
> (setting both generic banners and default banners), and it does not 
> appear to be looking at the banners.

Attached is the response I got from eEye about this issue; however please
note that an unpatched Stronghold 3.1 build 3016 is vulnerable to this
security issue, regardless of the output of this tool.

Cheers, Mark

Date: Mon, 24 Jun 2002 16:29:55 -0700
From: eEye Support <[email protected]>
To: Mark J Cox <[email protected]>
Subject: RE: false positives in Apache Scanning Tool? Or patches aren't 
    working?

We have updated the tool to v1.02, so please try it and see if it resolves
the issue.

Sincerely,

Technical Support Team
eEye Digital Security
http://www.eeye.com/support
IF YOU ARE NOT USING THE WEB SUPPORT FORM,
RESPONSE MAY BE SLOWER DUE TO MANUAL PROCESSING!
http://www.eeye.com/support


> -----Original Message-----
> From: Mark J Cox [mailto:[email protected]]
> Sent: Friday, June 21, 2002 10:55 AM
> Subject: Re: false positives in Apache Scanning Tool? Or patches aren't
> working?
>
>
> The Red Hat RPM's contain a backported version of the security patch
> rather than upgrading to Apache 1.3.26 that has been verified to fix the
> vulnerability.  My guess is that the Apache scanner simply looks at the
> server version string returned by the server to make it's assesment of if
> a site is vulnerable or not, since the server version string has not
> changed to Apache 1.3.26 this is why it is giving you a false positive.
>
> Cheers, Mark
> --
> Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation
> [email protected] // T: +44 798 061 3110 // F: +44 870 1319174
>
>
>
>