[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] openssl exploitable still?



Looking through my adm.serv adm_error logs i notice this:
 
[Mon Feb 16 04:13:42 2004] [notice] SIGUSR1 received.  Doing graceful restart
[Mon Feb 16 04:13:45 2004] [notice] Apache/1.3.20 Sun Cobalt (Unix) PHP/4.0.6 mod_ssl/2.8.4 OpenSSL/0.9.6 FrontPage/5.0.2.2510 mod_perl/1.26 $
[Mon Feb 16 09:35:54 2004] [error] mod_ssl: SSL handshake failed: HTTP spoken on HTTPS port; trying to send HTML error page (OpenSSL library $
[Mon Feb 16 09:35:54 2004] [error] OpenSSL: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request [Hint: speaking HTTP to HTTPS por$
[Mon Feb 16 09:36:09 2004] [error] mod_ssl: SSL handshake interrupted by system [Hint: Stop button pressed in browser?!] (System error follow$
[Mon Feb 16 09:36:09 2004] [error] System: Connection reset by peer (errno: 104)
[Mon Feb 16 09:36:30 2004] [error] mod_ssl: SSL handshake interrupted by system [Hint: Stop button pressed in browser?!] (System error follow$
[Mon Feb 16 09:36:30 2004] [error] System: Connection reset by peer (errno: 104)
[Mon Feb 16 09:36:56 2004] [error] mod_ssl: SSL handshake failed: HTTP spoken on HTTPS port; trying to send HTML error page (OpenSSL library $
[Mon Feb 16 09:36:56 2004] [error] OpenSSL: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request [Hint: speaking HTTP to HTTPS por$
[Mon Feb 16 11:47:08 2004] [error] ServerScriptHelper.ServerScriptHelper(): Cannot authenticate to CCE (login name: admin, session ID: FbbKsk$
[Tue Feb 17 04:27:41 2004] [notice] SIGUSR1 received.  Doing graceful restart
[Tue Feb 17 04:27:44 2004] [notice] Apache/1.3.20 Sun Cobalt (Unix) PHP/4.0.6 mod_ssl/2.8.4 OpenSSL/0.9.6 FrontPage/5.0.2.2510 mod_perl/1.26 $
[Tue Feb 17 06:31:23 2004] [error] mod_ssl: SSL handshake failed (server raptor.mydomain.com:81, client 200.51.38.2) (OpenSSL library err$
[Tue Feb 17 06:31:23 2004] [error] OpenSSL: error:1407609B:SSL routines:SSL23_GET_CLIENT_HELLO:https proxy request [Hint: speaking HTTP to HT$
[Tue Feb 17 06:31:53 2004] [error] mod_ssl: SSL handshake failed: HTTP spoken on HTTPS port; trying to send HTML error page (OpenSSL library $
[Tue Feb 17 06:31:53 2004] [error] OpenSSL: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request [Hint: speaking HTTP to HTTPS por$
[Tue Feb 17 06:31:54 2004] [error] mod_ssl: SSL handshake failed: HTTP spoken on HTTPS port; trying to send HTML error page (OpenSSL library $
[Tue Feb 17 06:31:54 2004] [error] OpenSSL: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request [Hint: speaking HTTP to HTTPS por$
[Tue Feb 17 07:46:54 2004] [error] ServerScriptHelper.ServerScriptHelper(): Cannot authenticate to CCE (login name: admin, session ID: FRiFeg$
[Tue Feb 17 12:00:33 2004] [error] [client 192.168.10.60] Invalid method in request s
[Tue Feb 17 12:00:46 2004] [error] [client 127.0.0.1] Invalid method in request s
 
[root admserv]# openssl
OpenSSL> version
OpenSSL 0.9.6 24 Sep 2000
OpenSSL>
Is my OpenSSL vunerable??
 
Thanks
Dave