Re: Apache vulnerability (mod_deflate)

Janne Johansson <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <CAA6-MF-KZjmvZZz69t1xB7R2GztBJchu1xXWeh2J8ibarhxWeQ@mail.gmail.com>
I think this commit to the FAQ show that the "it runs solaris" isn't true
anymore:
http://marc.info/?l=openbsd-cvs&m=123383404622677&w=2

Some 18 months ago or so.

2011/8/28 [email protected] <[email protected]>

> Maybe that is because web page is hosted on Solaris running in university
> of
> Alberta, Canada? ;-)
>
> apache itself in OpenBSD is not affected as you may test yourself
>
> -----Original message-----
> From: Alvaro Castillo
> Sent:  28/08/2011, 02:47
> To: [email protected]
> Subject: Apache vulnerability (mod_deflate)
>
>
> Hello, a friend shared me this vulnerability of mod_deflate of Apache
> and I have seen that OpenBSD.org is vulnerable.
>
> > perl killapache.pl www.openbsd.org 50
> host seems vuln
> ATTACKING www.openbsd.org [using 50 forks]
>
> Any suggestion?
>
> killapache.pl > http://www.exploit-db.com/exploits/17696/
>
> http://seclists.org/fulldisclosure/2011/Aug/178
>
> Cheers!
> netSys------
> http://www.byteandbit.info
>
>


-- 
 To our sweethearts and wives.  May they never meet. -- 19th century toast
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.