- Recommend:
- 0 Comments
Apache Web Server Flaw Found
Apache Foundation scrambles to fix 'major' hole that leaves servers open to attack.
A security flaw in the popular Apache Web server could allow a malicious hacker to launch a denial-of-service attack, or even take over a system on which the software is running, the Apache Software Foundation has warned.
The flaw relates to the way the Web server parses uploaded data, and can cause the software to misinterpret the size of incoming chunks of data, the organization reported in an advisory released on Monday.
Hackers could exploit the vulnerability by sending a carefully crafted request to a flawed Apache server, according to the foundation. The organization manages development of open-source Apache products.
Wide Effect
Affected are all versions of Apache 1.3 and versions of Apache 2 up to 2.0.36, the group said. The Apache Software Foundation said it is working on new software releases that will fix the flaw.
Exploiting the flaw successfully could help an attacker to stage a denial-of-service attack, making the server unreachable. In some cases attackers could run their choice of code on a server, the Foundation warned.
In a denial-of-service attack, a hacker places code on a number of vulnerable Web servers, then activates them simultaneously with the order to submit repeated requests for information from a single, separate Web site. The intention is to overload the targeted site and cause it to crash. Often, managers of the participating sites are unaware the sites are assisting in an attack.
Wicked With Windows
One particularly vulnerable group are users running Apache 1.x on Microsoft Windows 2000 or Windows 2000 Server, according to security software vendor Internet Security Systems (ISS) of Atlanta, which also issued its own advisory on Monday. An attacker targeting such a setup would likely be able to take control of the server, ISS said. In an e-mail alert, the organization characterized the hole as a "major" vulnerability.
More than 63 percent of all Web sites run on an Apache Web server, according to the British firm Netcraft, which compiles such information. The flaw is similar to a vulnerability in Internet Information Server (IIS) that Microsoft warned of last week, ISS said.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Geek Alert: Free Development Server Software XAMPP Helps Run Web Sites
- XAMPP for Windows
- Unpatched Apache Reverse Proxy Flaw Allows Access to Internal Network
- Google Wave Gets a Second Life from Apache
- Apache HTTP Server
- A Rivalry Emerges As Apache Asserts OpenOffice Plans
- Coming Soon: An 'IBM Edition' of Apache OpenOffice
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.















