|
|
Log in / Subscribe / Register

Surge in Scans Seeking SSL Servers (Netcraft)

Netcraft reports that Internet scanning for servers running Secure Sockets Layer (SSL) has spiked in the past week. "Security firms are advising network administrators to install security patches for SSL servers, including a recent update for mod_ssl, which is widely used in Apache servers running OpenSSL. A security update was released July 16 to fix the vulnerability, which may allow a remote attacker to execute arbitrary code when Apache is configured to use mod_ssl and mod_proxy, according to an advisory from Gentoo Linux."

to post comments

Surge in Scans Seeking SSL Servers (Netcraft)

Posted Aug 2, 2004 18:05 UTC (Mon) by tseaver (guest, #1544) [Link] (1 responses)

The mod_ssl vulnerability only affects Apache 1.3.x:

We've today found an ssl_log() related format string vulnerability in
the mod_proxy hook functions of mod_ssl for Apache 1.3.x (mod_ssl for
Apache 2.x is not affected). A mod_ssl 2.8.19 for Apache 1.3.31 was
created which fixes this potential security hole.

Surge in Scans Seeking SSL Servers (Netcraft)

Posted Aug 2, 2004 19:22 UTC (Mon) by komarek (guest, #7295) [Link]

Thank-you for clarifying the version issue. One would think that Netcraft would manage to include versions in main article.

-Paul Komarek


Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds