Re: Apache worm in the wild

From: Brett Glass (brett@lariat.org)
Date: 06/28/02


Date: Fri, 28 Jun 2002 11:27:13 -0600
To: flynn@energyhq.homeip.net, Domas Mituzas <domas.mituzas@microlink.lt>
From: Brett Glass <brett@lariat.org>

At 05:38 AM 6/28/2002, flynn@energyhq.homeip.net wrote:

>I wonder how many variants of this kind of thing we'll see, but I assume most people
>running Apache have upgraded already.

Upgrading Apache may prevent your system from being taken over,
but it doesn't necessarily prevent it from being DoSed. One of
my Apache servers, which had been upgraded to 2.0.39, went berserk
on June 25th, spawning the maximum number of child processes and
then locking up. The server did not appear to have been infiltrated,
but the logs were filled with megabytes of messages indicating that
the child processes were repeatedly trying to free chunks of memory
that were already free. Probably the result of an attempted exploit
going awry. (It could have been aimed at Linux, or at a different
version of Apache; can't tell. But clearly it got somewhere, though
not all the way.)

--Brett

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Ports after upgrade
    ... You should try to use portsnap instead of cvsup which is in the base since 6.2. ... Your problem looks like a portupgrade mistake. ... After upgrading portupgrade you should rebuild apache with something like that: ...
    (freebsd-questions)
  • Re: How to manually patch/configure/compile Apache 2.2.4s mod_autoindex module?
    ... Apache 2.2.4, which apart from some hassles when upgrading the PHP4 ... this user, I had allowed directory listings, with fancyindexing ... Overriding the Default Ports Directories ...
    (freebsd-questions)
  • Re: Apache worm in the wild
    ... Upgrading Apache may prevent your system from being taken over, ... the child processes were repeatedly trying to free chunks of memory ...
    (FreeBSD-Security)
  • Re: Apache worm in the wild
    ... Upgrading Apache may prevent your system from being taken over, ... the child processes were repeatedly trying to free chunks of memory ...
    (Bugtraq)
  • How to manually patch/configure/compile Apache 2.2.4s mod_autoindex module?
    ... I used to use Apache 1.3.33 on my live server, and recently I upgraded to Apache 2.2.4, which apart from some hassles when upgrading the PHP4 extensions, went well. ... However, there is one small thingy that is different: there are exactly two directories on which I allow directory listings, and these listings are called from an external W*nd*ws program that one of the users of my machine has made and has distributed. ... In fact, it looks like the only place where this could be changed, is the mod_autoindex.c file, under the "work" directory in the proper "ports" directory. ...
    (freebsd-questions)

Quantcast