ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

SGI warns of Web server vulnerability

Matthew Broersma ZDNet.co.uk

Published: 20 Mar 2002 14:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Silicon Graphics (SGI) machines running the Apache Web server on SGI's IRIX operating system are vulnerable to attack by hackers, who may be able to gain administrator-level access, the company has warned.

The company makes machines used for everything from scientific research to movie special effects, and many are used by government and defence organisations. The two new flaws, originally announced on Friday, affect IRIX versions 6.5.12, 6.5.13 and 6.5.14 running Apache versions prior to 1.3.22. IRIX is SGI's proprietary version of the Unix operating system, while Apache is an widely used open-source Web server, which is installed and enabled by default on IRIX.

One vulenerability was found in Apache's split-logfile program, a tool used to manage system files called logfiles. SGI said that if the feature is turned on, a specially crafted request could allow any file with a .log extension on the system to be written to, which could be used to give an attacker full access to the system. Split-logfile is not turned on by default.

The second bug was found in Apache's Multiviews facility, which is used for customising the way content is presented to Web browsers. In some configurations, it is possible to enter a specially formed query to return a directory listing, which could allow an attacker to discover the locations of sensitive files on the system.

SGI hasn't released a patch for the flaws, but instead recommends that users upgrade to an operating system newer than 6.5.14, which includes a newer version of Apache in which the problems have been resolved. If the software can't be upgraded immediately, the company recommends disabling Apache.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
59 out of 86 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Linux Administrator Apache, MySQL, PHP, DNS, Web Servers, Brighton

Linux Systems Administrator Apache, MySQL, PHP, DNS, DR, Web Servers, Brighton 30k My client is currently recruiting for a Linux Systems ...

Linux Systems Administrator Linux, MySQL, Apache, Tomcat, London 40k

Linux Systems Administrator Linux, MySQL, Apache, Tomcat, London 40k My client is a fast growing comparison website, which offer services to the ...

Applications Support Technician / 1st and 2nd Line Helpdesk Engineer - UNIX, Windows, Linux, Networking - Central London, WC2

The Applications Support Technician / 1st and 2nd Line Helpdesk Engineer role is a technical role which involves being hands on with our core Linux ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains