User User name Password  
   
Sunday 22.12.2024 / 00:21
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > general discussion > afterdawn feedback & suggestions > update webserver?
Show topics
 
Forums
Forums
Update WebServer?
  Jump to:
 
Posted Message
Senior Member
_
11. November 2008 @ 07:36 _ Link to this message    Send private message to this user   
I see that Afterdawn is using Apache 2.2.3. Shouldn't it be updated to 2.2.10? 2.2.3 has quite a number of vulnerabilities.... especially exploited by those who break the rules and get banned...lol

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

Advertisement
_
__
Admin

9 product reviews
_
12. November 2008 @ 07:39 _ Link to this message    Send private message to this user   
Originally posted by cdavfrew:
I see that Afterdawn is using Apache 2.2.3. Shouldn't it be updated to 2.2.10? 2.2.3 has quite a number of vulnerabilities.... especially exploited by those who break the rules and get banned...lol

Best Regards :D
Thanks for the tip! =) We live by the CentOS update schedule, and 2.2.3 is the latest version of Apache available for the time being.

Apache versions between 2.2.3 and 2.2.10 have patched only minor vulnerabilities - all of them in modules not used by us. Or am I mistaken?


Jari Ketola
Administrator
http://www.AfterDawn.com
Senior Member
_
12. November 2008 @ 08:11 _ Link to this message    Send private message to this user   
Thanks for your reply.

I was actually more concerned about these updates found in 2.2.6:

Quote:
A bug was found in the mod_cache module. On sites where caching is enabled, a remote attacker could send a carefully crafted request that would cause the Apache child process handling that request to crash. This could lead to a denial of service if using a threaded Multi-Processing Module.
Quote:
The recall_headers function in mod_mem_cache in Apache 2.2.4 did not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
Quote:
The Apache HTTP server did not verify that a process was an Apache child process before sending it signals. A local attacker with the ability to run scripts on the HTTP server could manipulate the scoreboard and cause arbitrary processes to be terminated which could lead to a denial of service.
The other updates in 2.2.8 and higher don't really concern AfterDawn's active modules (at least those I know about...), unless there is a FTP server within AfterDawn as well.

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

This message has been edited since posting. Last time this message was edited on 12. November 2008 @ 08:13

Admin

9 product reviews
_
12. November 2008 @ 09:39 _ Link to this message    Send private message to this user   
Actually we don't use mod_cache (or mod_mem_cache for that matter) at AfterDawn. Local attacks aren't a concern either since no-one outside the company has access to the servers.


Jari Ketola
Administrator
http://www.AfterDawn.com
Advertisement
_
__
 
_
Senior Member
_
12. November 2008 @ 22:12 _ Link to this message    Send private message to this user   
Ok then. Thanks for clarifying! :)

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

afterdawn.com > forums > general discussion > afterdawn feedback & suggestions > update webserver?
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2024 by AfterDawn Ltd.

  IDG TechNetwork