Re: help in patching
Mark J Cox <[email protected]> Wed, 26 Jun 2002 12:44:27 +0100 (BST)
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
> I have tested the tool with patched, and unpatched versions of 1.3.20 > (setting both generic banners and default banners), and it does not > appear to be looking at the banners. Attached is the response I got from eEye about this issue; however please note that an unpatched Stronghold 3.1 build 3016 is vulnerable to this security issue, regardless of the output of this tool. Cheers, Mark Date: Mon, 24 Jun 2002 16:29:55 -0700 From: eEye Support <[email protected]> To: Mark J Cox <[email protected]> Subject: RE: false positives in Apache Scanning Tool? Or patches aren't working? We have updated the tool to v1.02, so please try it and see if it resolves the issue. Sincerely, Technical Support Team eEye Digital Security http://www.eeye.com/support IF YOU ARE NOT USING THE WEB SUPPORT FORM, RESPONSE MAY BE SLOWER DUE TO MANUAL PROCESSING! http://www.eeye.com/support > -----Original Message----- > From: Mark J Cox [mailto:[email protected]] > Sent: Friday, June 21, 2002 10:55 AM > Subject: Re: false positives in Apache Scanning Tool? Or patches aren't > working? > > > The Red Hat RPM's contain a backported version of the security patch > rather than upgrading to Apache 1.3.26 that has been verified to fix the > vulnerability. My guess is that the Apache scanner simply looks at the > server version string returned by the server to make it's assesment of if > a site is vulnerable or not, since the server version string has not > changed to Apache 1.3.26 this is why it is giving you a false positive. > > Cheers, Mark > -- > Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation > [email protected] // T: +44 798 061 3110 // F: +44 870 1319174 > > > >