Re: Apache vulnerability checking

From: Syzop (syz@dds.nl)
Date: 06/25/02


Date: Tue, 25 Jun 2002 00:38:51 +0200
From: Syzop <syz@dds.nl>
To: Toni Heinonen <Toni.Heinonen@teleware.fi>

Hi,

Toni Heinonen wrote:

> > Full server version:
> > "Server: Apache/1.3.24 (Unix) (Red-Hat/Linux) mod_ssl/2.8.8
> > OpenSSL/0.9.6b mod_perl/1.26"

[..]

> Indeed, Red Hat 7.2 carries Apache 1.3.22 and 7.3 has 1.3.23, and

note that this server is running 1.3.24... I'm not sure how they do that
since they also have Red-Hat/Linux in their server header...

> For instance, eEye's tool reports my patched RH7.2 server as
> "vulnerable", because it only checks the server string, it doesn't try
> to exploit the vulnerability.

Could you try my 'checkap' against your redhat server?

I didn't know eEye's tool only checked the version, pretty strange since
it's easy to make something like I did. Ofcourse in case someone is using
apache 2.x + multiple connections per child or something = some other
clients will be killed too... maybe they didn't want to take that risk.

Thanks for the information,

    Bram Matthys.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #142
    ... MICROSOFT VULNERABILITY SUMMARY ... Mollensoft Enceladus Server Suite Clear Text Password Storage... ... FakeBO Syslog Format String Vulnerability ... Methodus 3 Web Server File Disclosure Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #139
    ... OFF any Windows 2000 Managed Dedicated Hosting Solution from Interland. ... Sun ONE Application Server Plaintext Password Vulnerability ... Batalla Naval Remote Buffer Overflow Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #140
    ... Cafelog b2 Remote File Include Vulnerability ... Webfroot Shoutbox Remote Command Execution Vulnerability ... Pablo Software Solutions Baby POP3 Server Multiple Connection... ... Microsoft Windows XP Nested Directory Denial of Service... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter # 150
    ... - automatically set positive security policies for real-time protection, ... MICROSOFT VULNERABILITY SUMMARY ... Meteor FTP Server USER Memory Corruption Vulnerability ... MDaemon SMTP Server Null Password Authentication Vulnerabili... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #152
    ... MICROSOFT VULNERABILITY SUMMARY ... Real Networks Helix Universal Server Remote Buffer Overflow ... ... NEW PRODUCTS FOR MICROSOFT PLATFORMS ...
    (Focus-Microsoft)