Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

If you haven't heard... time to upgrade 1

Status
Not open for further replies.

GoldenEternity

Technical User
May 4, 2001
159
US
If you haven't already heard, there has been a remote command execution vulnerability found in all versions of Apache. Last week, GOBBLES released a proof of concept exploit to demonstrate that not only does the hole give root, but that it will give root on OpenBSD.

This exploit is in the wild, and is likely the entry point for the monkey.org hack a few weeks back where the source code on the site was backdoored.

New versions of apache are out to fix this vuln, but be on the lookout. GOBBLES warns that they have been working on other holes in Apache as well... Given their track record, I'd believe it.
 
Thanks for the info. ---------------------------------------
If someone's post was helpful to you, please click the box "Click here to mark this post as a helpful or expert post".
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top