[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Apache Chunked Vulnerability and Cobalt servers



On Thursday 18 April 2002 10:36 am, Paul Fennell wrote:
> EH >>> ??
>
> What's that to do with the price of apples ?
> Nobody mention hacking in this thread .
> Your getting mixed up...
>
> I want info on how to upgrade my version of apache to 1.30.26
> on a raq4 .. and David Is looking to see if Sun/cobalt is making a patch
> for us ?
>
WOW do these threads ever get screwed up on this list....
This thread started as 
"Urgent - Fans needed"  then became
"Apache Chunked Vulnerability"

It would be relatively simple to update httpd
save /usr/sbin/httpd
get source
configure
compile
copy new httpd to /usr/sbin/
restart httpd

the difficult task would be to update ahttpd (cobalt mods)
One solution may be to configure ipchains to only allow access to ports 81 
and 444 from *your' ip address.

-- 
Gerald Waugh 
http://frontstreetnetworks.com  SOHO Networks & Web Site Hosting
Front Street Networks LLC     voice +1 203 785 0699 * fax +1 203 785 1787
229 Front Street, Ste. #C, New Haven CT 06513-3203