Re: Apache vulnerability (mod_deflate)

Tomas Bodzar <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <CAK3FJdn_30NF=9U3qDkv9hBU9Yzapbyd0Xkvp9LjgxNPSz8Jag@mail.gmail.com>
On Wed, Aug 31, 2011 at 4:45 PM, Janne Johansson <[email protected]> wrote:
> I think this commit to the FAQ show that the "it runs solaris" isn't true
> anymore:
> http://marc.info/?l=openbsd-cvs&m=123383404622677&w=2
> Some 18 months ago or so.

Interesting, seems like OpenBSD is used. Does it mean that whole
university switched to OpenBSD or there's some forward in place?


>
> 2011/8/28 [email protected] <[email protected]>
>>
>> Maybe that is because web page is hosted on Solaris running in university
>> of
>> Alberta, Canada? ;-)
>>
>> apache itself in OpenBSD is not affected as you may test yourself
>>
>> -----Original message-----
>> From: Alvaro Castillo
>> Sent: B 28/08/2011, 02:47
>> To: [email protected]
>> Subject: Apache vulnerability (mod_deflate)
>>
>>
>> Hello, a friend shared me this vulnerability of mod_deflate of Apache
>> and I have seen that OpenBSD.org is vulnerable.
>>
>> > perl killapache.pl www.openbsd.org 50
>> host seems vuln
>> ATTACKING www.openbsd.org [using 50 forks]
>>
>> Any suggestion?
>>
>> killapache.pl > http://www.exploit-db.com/exploits/17696/
>>
>> http://seclists.org/fulldisclosure/2011/Aug/178
>>
>> Cheers!
>> netSys------
>> http://www.byteandbit.info
>>
>
>
>
> --
> B To our sweethearts and wives.B  May they never meet. -- 19th century
toast
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.