Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Attacks increase on Apache servers

John McCormick

Published: 11 Dec 2002 11:59 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

I report on a lot of software vulnerabilities here, and I try to weed out the unimportant ones. But there's no real way to know in advance which ones will be exploited and which ones cybervandals will essentially ignore. Some critical vulnerabilities never become a big danger, even when administrators fail to patch them. This makes it difficult to defend the expense of constantly updating and maintaining system patches and probably leads to a lot of the complacency we see in information security.

Of course, other vulnerabilities become major attack vectors for hackers. This has been the case recently with a slew of Apache Web server vulnerabilities.

Details
ESecurityplanet.com has reported that the Apache software, which is used by about 60 percent of Web servers, is being actively attacked on the Internet. The Apache HTTP Server Project warns of open holes in many installed versions of Apache and urgently recommends that admins upgrade to version 1.3.27 or 2.0.43 or later, which were still the latest versions available as of mid-November.

An Internetnews.com report published on Oct. 4, 2002, said that version 1.3.27 patched three key vulnerabilities. One hole is found in all versions of Apache prior to 1.3.27 on "platforms using System V shared memory based scoreboards." That vulnerability can cause a denial of service event. Another flaw relates to cross-site scripting in the default 404 page, while the third vulnerability that's repaired in this 1.3.27 bug-fix release was a buffer overflow threat.

Although the latest release was produced mainly to patch these three vulnerabilities, systems still running version 1.2 will, according to the Apache Foundation, also find expanded platform support and improved performance if they upgrade to the latest 1.3 version. For a quick summary of some other details regarding the new release, see the Internetnews.com report.

The latest Apache Foundation warning posted on BugTraq cautions that the mod_ssl slapper worm is still being used successfully to attack Apache servers. This is an OpenSSL source problem and doesn't require an Apache upgrade but requires an OpenSSL library update. Thus, those running an SSL-enabled server should upgrade to version 0.9.6e or later of OpenSSL and recompile.

Vulnerabilities that are being exploited because of a failure to upgrade Apache itself include the 404 page cross-site scripting bug, which manages wildcard DNS lookups; buffer overflows in the ApacheBench (ab) utility; and htpasswd and htdigest vulnerabilities.

Applicability
The vulnerabilities affect Apache HTTP Server versions prior to 1.3.27 or version 2 prior to 2.0.43.

Risk level -- serious
These vulnerabilities are actually being exploited right now -- this isn't just a theoretical possibility -- so that makes it especially important that the flaws are fixed.

Fix
Update Apache and OpenSSL. Apache has posted the upgrade here.

Final word
This is just the latest in a series of threats to vital Internet infrastructure elements, following on the recent partially successful attempt to bring down the DNS root servers on the Internet. As security professionals, we sometimes turn a blind eye to problems that affect only home users or companies that fail to fix their own vulnerable software. But there is rising concern that terrorists may begin to launch systematic attacks on the Internet because of its importance to the world economy. We need to be especially vigilant in updating systems such as Apache that make up a piece of the Internet -- both to keep those systems from being attacked and from being used to attack others.


Have your say instantly in the Tech Update forum.

Find out what's where in the new Tech Update with our Guided Tour.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
33 out of 81 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters