ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Attacks increase on Apache servers

John McCormick

Published: 11 Dec 2002 11:59 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

I report on a lot of software vulnerabilities here, and I try to weed out the unimportant ones. But there's no real way to know in advance which ones will be exploited and which ones cybervandals will essentially ignore. Some critical vulnerabilities never become a big danger, even when administrators fail to patch them. This makes it difficult to defend the expense of constantly updating and maintaining system patches and probably leads to a lot of the complacency we see in information security.

Of course, other vulnerabilities become major attack vectors for hackers. This has been the case recently with a slew of Apache Web server vulnerabilities.

Details
ESecurityplanet.com has reported that the Apache software, which is used by about 60 percent of Web servers, is being actively attacked on the Internet. The Apache HTTP Server Project warns of open holes in many installed versions of Apache and urgently recommends that admins upgrade to version 1.3.27 or 2.0.43 or later, which were still the latest versions available as of mid-November.

An Internetnews.com report published on Oct. 4, 2002, said that version 1.3.27 patched three key vulnerabilities. One hole is found in all versions of Apache prior to 1.3.27 on "platforms using System V shared memory based scoreboards." That vulnerability can cause a denial of service event. Another flaw relates to cross-site scripting in the default 404 page, while the third vulnerability that's repaired in this 1.3.27 bug-fix release was a buffer overflow threat.

Although the latest release was produced mainly to patch these three vulnerabilities, systems still running version 1.2 will, according to the Apache Foundation, also find expanded platform support and improved performance if they upgrade to the latest 1.3 version. For a quick summary of some other details regarding the new release, see the Internetnews.com report.

The latest Apache Foundation warning posted on BugTraq cautions that the mod_ssl slapper worm is still being used successfully to attack Apache servers. This is an OpenSSL source problem and doesn't require an Apache upgrade but requires an OpenSSL library update. Thus, those running an SSL-enabled server should upgrade to version 0.9.6e or later of OpenSSL and recompile.

Vulnerabilities that are being exploited because of a failure to upgrade Apache itself include the 404 page cross-site scripting bug, which manages wildcard DNS lookups; buffer overflows in the ApacheBench (ab) utility; and htpasswd and htdigest vulnerabilities.

Applicability
The vulnerabilities affect Apache HTTP Server versions prior to 1.3.27 or version 2 prior to 2.0.43.

Risk level -- serious
These vulnerabilities are actually being exploited right now -- this isn't just a theoretical possibility -- so that makes it especially important that the flaws are fixed.

Fix
Update Apache and OpenSSL. Apache has posted the upgrade here.

Final word
This is just the latest in a series of threats to vital Internet infrastructure elements, following on the recent partially successful attempt to bring down the DNS root servers on the Internet. As security professionals, we sometimes turn a blind eye to problems that affect only home users or companies that fail to fix their own vulnerable software. But there is rising concern that terrorists may begin to launch systematic attacks on the Internet because of its importance to the world economy. We need to be especially vigilant in updating systems such as Apache that make up a piece of the Internet -- both to keep those systems from being attacked and from being used to attack others.


Have your say instantly in the Tech Update forum.

Find out what's where in the new Tech Update with our Guided Tour.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
33 out of 81 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Internet Team Leader

Extensive working knowledge of QMail, Squid, Proftp and Apache. Good working knowledge of scripting languages i.e. To ensure that all Linux related ...

System Administrator Linux Level 2 ( RedHat, Linux+, SQL ) West London

Apache, Mail transfer agents (sendmail, postfix, qmail), FTP, SSH and DNS)  Technical certifications (i.e. Requirements You must also have ...

Do you want to work for the best ? Linux, Unix, Systems Administration

You must have working knowledge of Linux, Unix, (Apache), databases (PostgreSQL / MySQL) as well as Networking, monitoring, and scripting. The role ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec