Apache 1.3.XX

From: John (johns@tampabay.rr.com)
Date: 01/31/02


From: "John" <johns@tampabay.rr.com>
To: <incidents@securityfocus.com>
Date: Wed, 30 Jan 2002 21:22:04 -0500

Hello list,

  I was wondering if anyone has heard about an Apache 1.3.XX bug starting to
surface. Supposedly it creates a bind shell on TCP 2029 when this code
executes the payload. The exploit has "7350apache - Apache 1.3.XX remote
root exploit" in the binary (along with some other stuff that I don't want
to say on the list). I don't have access to this binary and that's why I am
curious as to if other people on this list have seen anything lately.

Have a great night.

This message and any attachment are confidential and may be privileged or
otherwise protected from disclosure. If you are not the intended recipient,
please telephone, fax or e-mail to the sender without delay. Return this
message or delete this message and any attachment from your system as per
our request. If you are not the intended recipient you must not copy this
message or attachments or disclose the contents to any other person.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • RE: Oracle 10g + Linux RHEL 4 + Perl + DBI = OCIEnvNlsCreate Error (!?!?)
    ... The owner of the Apache software? ... Se voce recebeu esta mensagem por engano, ... This e-mail is meant only for the intended recipient of the ... notify us immediately of the error by return e-mail and please delete ...
    (perl.dbi.users)
  • [Full-Disclosure] re: zen-parse@gmx.de is not zen-parse@gmx.net
    ... > iDefense approach "reasonable disclosure". ... > disclose critical information on new security vulnerabilities to ... In the case of the apache shared memory ownership, ...
    (Full-Disclosure)
  • RE: FP 2002 extentions
    ... Check Apache version: ... >by the attorney-client privilege or other privileges or protections ... >delivering the document to the intended recipient, ... This communication may contain material protected by the attorney-client privilege or other privileges or protections from discovery, such as the physician-patient privilege, or a peer review privilege, such as California Evidence Code Section 1157. ...
    (RedHat)
  • RE: Strange found in apache error.log
    ... Files with extension not associated with any filter can be executed as ... PHP scripts in Apache. ... 218.156.221.22] client denied by server configuration: ... It is for the intended recipient only. ...
    (Security-Basics)
  • RE: FP 2002 extentions
    ... Do I need to restart apache? ... >Protect your PC - get McAfee.com VirusScan Online ... >discovery, such as the physician-patient privilege, or a peer review ... >the intended recipient or the individual responsible for delivering the ...
    (RedHat)