[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] Apache worm that uses the chunk vulnerability - in the wild



At 03:14 PM 6/28/2002, you wrote:
Domas Mituzkas just reported that he found the sourcecode:

http://dammit.lt/apache-worm/apache-worm.c

Normally I don't post spoilers of this sort, but special times, special means.
So although it has NOT yet been officially  announced: The updated Apache
PKGs for some Cobalts have been uploaded to the Cobalt FTP server:

I read through the code and I would think this worm would work for any webserver not just apache... but that is not the case....
What other BIG problems does apache have that we don't know about?.
Everyone complains about all the holes in IIS, but that's because microsoft tells us about them... apache should do the same thing!