Re: Apache-Nosejob

From: Muhammad Faisal Rauf Danka (mfrd@attitudex.com)
Date: 08/23/02


Date: Fri, 23 Aug 2002 13:54:21 -0700 (PDT)
From: Muhammad Faisal Rauf Danka <mfrd@attitudex.com>
To: vuln-dev@securityfocus.com, pen-test@securityfocus.com

Excuse me Mr gotcha but,
apache-nosejob is for OpenBSD 3.0/3.1 , FreeBSD 4.5 and NetBSD 1.5.2 running vulnerable versions of Apache.

You can't use the same one for spawning rootshell on Linux and Solaris SPARC/x86 etc.

Apache Exploits for Solaris SPARC/x86 and linux have not been officially released yet.

Regards
--------
Muhammad Faisal Rauf Danka

Head of GemSEC / Chief Technology Officer
Gem Internet Services (Pvt) Ltd.
web: www.gem.net.pk
Key Id: 0x784B0202
Key Fingerprint: 6F8C EDCF 6C6E 06A5 48D7 6A20 C592 484B
784B 0202

_____________________________________________________________
---------------------------
[ATTITUDEX.COM]
http://www.attitudex.com/
---------------------------

_____________________________________________________________
Promote your group and strengthen ties to your members with email@yourgroup.org by Everyone.net http://www.everyone.net/?btn=tag



Relevant Pages

  • [UNIX] "Slapper" OpenSSL/Apache Worm Propagation
    ... The worm is a modified derivative of the Apache ... Current versions of the Slapper worm only target the following Linux ... Mod_ssl is the Apache web server interface to OpenSSL, ...
    (Securiteam)
  • Re: (Another) simple benchmark
    ... Interesting that the linux you are claiming to use would use prefork ... Apache as default, while this is the default on FreeBSD I would think ... the threaded worker would be used on a lot of linux dists, since they don't have the option to easily rebuild it. ...
    (freebsd-performance)
  • Re: [PHP] Copy Function Errors
    ... default most linux distributions do not give apache a password. ... Try testing to make sure you can ftp to the server using a normal ftp ... Subject: Copy Function Errors ...
    (php.general)
  • Re: (Another) simple benchmark
    ... In absence of anything smarter to do, I installed WBEL 3 Linux ... Apache is a well known server-grade product, ... It shouldn't behave this badly on FreeBSD. ... FreeBSD CPU time was 100% spent, with 90%-95% spent in sys time ...
    (freebsd-current)
  • Re: (Another) simple benchmark
    ... In absence of anything smarter to do, I installed WBEL 3 Linux ... Apache is a well known server-grade product, ... It shouldn't behave this badly on FreeBSD. ... FreeBSD CPU time was 100% spent, with 90%-95% spent in sys time ...
    (freebsd-performance)