Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 27
  1. #1
    Member
    Join Date
    May 2002
    Posts
    429

    Default Apache Info = Security

    If you have used this How-To :

    http://forum.rackshack.net/showthrea...de+apache+info

    then WHM will not show you if your Apache is vulnerable (and it wont prompt you to upgrade / run easyapache)

    So it would be nice if Nick or CpanelJosh could make a sticky (for a day or two) when there is something that needs to be upgraded (apache related)

    cPanel.net Support Ticket Number:

  2. #2
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    So this message is sticky...does that mean apache needs to be updated? I have version 1.3.27 already, but yeah, I turned tokens off. Is there something in apache that needs to be updated even though the version has not changed?

    cPanel.net Support Ticket Number:

  3. #3
    Member
    Join Date
    May 2002
    Posts
    429

    Default

    There is new Frontpage extensions package (old one is vulnerable), turn tokens on for a minute or two and you will see (then you can turn it off again)

    cPanel.net Support Ticket Number:

  4. #4
    Member
    Join Date
    Apr 2003
    Location
    New Jersey, USA
    Posts
    414

    Default

    Im running:

    WHM 7.2.0 Cpanel 7.2.0-R43
    Apache Core 1.3.27
    Bytes Logger 1.2
    Bandwidth Limiter 1.0
    PHP 4.3.2
    FrontPage 5.0.2.2634
    mod_ssl 2.8.14


    Should I still follow that walk through?

    cPanel.net Support Ticket Number:

  5. #5
    Member
    Join Date
    May 2002
    Posts
    429

    Default

    is the padlock next to installaed aplications closed or opened?

    cPanel.net Support Ticket Number:

  6. #6
    Member
    Join Date
    Apr 2003
    Location
    New Jersey, USA
    Posts
    414

    Default

    all closed

    cPanel.net Support Ticket Number:

  7. #7
    Member
    Join Date
    May 2002
    Posts
    429

    Default

    Then it's all ok

    cPanel.net Support Ticket Number:

  8. #8
    Member
    Join Date
    May 2002
    Posts
    429

    Default

    FrontPage 5.0.2.2634 (this was the update)

    cPanel.net Support Ticket Number:

  9. #9
    Member
    Join Date
    Apr 2003
    Location
    New Jersey, USA
    Posts
    414

    Default

    ahh..Thanks for the nice responses.

    cPanel.net Support Ticket Number:

  10. #10
    Member
    Join Date
    Jun 2002
    Posts
    78

    Default

    Just so you know Apache 1.3.28 has been released and the lock is again open in WHM....

    cPanel.net Support Ticket Number:

  11. #11
    Member
    Join Date
    May 2003
    Posts
    610

    Default

    What does Apache 1.28 have that 1.27 doesn't? What's vulnerable with 1.27?

    cPanel.net Support Ticket Number:

  12. #12
    Member EcpHosting's Avatar
    Join Date
    Dec 2002
    Posts
    70

    Default

    Yes, what is the difference? We JUST upgraded apache on all machines (for the new FrontPage patch) and now another upgrade is needed?! I dont mind doing it (we test it on our test machine and then apply it to the others), but I would like to know what is going on with this new update.

    cPanel.net Support Ticket Number:
    Erik - Operations Manager
    :::: ecphosting.net ::::
    aim, msn, yahoo: EcpErik

  13. #13
    Member
    Join Date
    Apr 2003
    Posts
    243

    Default

    I think the thing which most people will be interested in is

    *) Prevent the server from crashing when entering infinite loops. The
    new LimitInternalRecursion directive configures limits of subsequent
    internal redirects and nested subrequests, after which the request
    will be aborted. PR 19753 (and probably others).
    [William Rowe, Jeff Trawick, Jim Jagielski, André Malo]
    and

    *) backport from 2.x series: Prevent endless loops of internal redirects
    in mod_rewrite by aborting after exceeding a limit of internal redirects.
    The limit defaults to 10 and can be changed using the RewriteOptions
    directive. PR 17462. [André Malo]
    There is also some stuff to prevent fd leakage

    Certain 3rd party modules would bypass the Apache API and not
    invoke ap_cleanup_for_exec() before creating sub-processes.
    To such a child process, Apache's file descriptors (lock
    fd's, log files, sockets) were accessible, allowing them
    direct access to Apache log file etc. Where the OS allows,
    we now add proactive close functions to prevent these file
    descriptors from leaking to the child processes.
    [Jim Jagielski, Martin Kraemer]
    You can see the full list @ http://www.apache.org/dist/httpd/CHANGES_1.3
    cPanel.net Support Ticket Number:

  14. #14
    Member EcpHosting's Avatar
    Join Date
    Dec 2002
    Posts
    70

    Default

    Thanks for the link to the apache changes! That's what we were looking for.

    cPanel.net Support Ticket Number:
    Erik - Operations Manager
    :::: ecphosting.net ::::
    aim, msn, yahoo: EcpErik

  15. #15
    Member
    Join Date
    Apr 2003
    Posts
    16

    Default Re: Apache Info = Security

    Originally posted by Angel78
    If you have used this How-To :

    http://forum.rackshack.net/showthrea...de+apache+info

    then WHM will not show you if your Apache is vulnerable (and it wont prompt you to upgrade / run easyapache)

    So it would be nice if Nick or CpanelJosh could make a sticky (for a day or two) when there is something that needs to be upgraded (apache related)

    cPanel.net Support Ticket Number:

    RIGHT

    i use into 9 server
    ServerSignature Off

    and into 2
    ServerSignature YES

    in this way i look when i must update APACHE..but i would like have all server with
    ServerSignature Off


    UP THREAD!

    cPanel.net Support Ticket Number:

Similar Threads & Tags
Similar threads

  1. Help: CPanel Security Problem - www.step57.info
    By natfirst in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-23-2006, 11:23 AM
  2. Server info (apache too ?)
    By drumhtd in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-18-2005, 03:11 PM
  3. proftpd security vulerability??? Where can I find more info?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 25
    Last Post: 07-20-2005, 04:59 AM
  4. Is the info that's put into the mail headers a security risk?
    By damainman in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-19-2004, 06:01 PM
  5. Emergency apache build info needed.
    By xWho in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-07-2004, 03:07 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube