Berkeley CSUA MOTD:Entry 25167
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/05/24 [General] UID:1000 Activity:popular
5/24    

2002/6/21-23 [Computer/SW/Security, Computer/SW/WWW/Server] UID:25167 Activity:very high
6/21    Big bad apache hole in the wild.  Patch/upgrade now.  See http://apache.org
        or your favorite security site for details.
        \_ So they finally learned from Microshit?  "In order to gain free
           press we need to introduce security holes."
        \_ Does anyone think this vulnerability could lead to a fast spreading
           worm like  Code Red, for example?
        \_ What's the point? Apache + modules (esp. php) are full of holes.
           \_ So, don't use the modules you don't trust.
           Patch one, and there are still a hundred others that the '1337
           H4X0R5 will use to break in. Even if you patch all the modules,
           you still have all your executable content (perl cgi, ssi, php,
           servlet, jsp, etc) which is undoubtedly riddled with holes.
              \_ 1) try formatting.  2) just because there are other holes is
                 no reason not to patch this one.  3) glad you're not the admin
                 at my company.
           \_ It is possible but cracking a site by exploiting the holes
              in locally written code is much harder than exploiting a widely
              publicized and well understood vulnerability that possibly
              affects nearly every apache site out there.
           If you care about security, run publicfile.
           \_ publicfile does not support CGI scripts or any kind of server
              side programming which makes it fairly useless for lots of
              users.
        \_ Um, it's not actually that bad.  It's a DoS exploit at worst on
           many architectures.
           \_ nnnn!  go read the security alert, not msnbc.
              \_ Actually I read all three.  Plus the apache one.  Plus the
                 debian security-announce summary.  It's a DoS explot.
                 \_ Well you didn't read the one that said it's a full root
                    exploit.  Whatever, go use telnet.  Not my problem.
                 \_ At least one exploit (for openbsd) has already been posted
                    on bugtraq with intent to prove people like you wrong.
                    \_ If your OS doesn't execute data off the stack, it's
                       not exploitable (but it's still DOS).  And it's not
                       a root hole, just the user Apache runs as.  Still,
                       it's potentially bad.  -tom
                       \_ Lots of people run apache as root.  Lots of sites
                          that run apache as 'www' or whatever will also have
                          local holes if they haven't fixed this one.  Thus it
                          is highly likely that getting in through apache is
                          just one step from root.  Layers....
                          \_ I challenge you to find one person running
                             Apache as root.  -tom
                             \- the csua used to run a WEEB server on it's
                             name server. there was a bug that let you get
                             a shell running as the WEEB server uid. now it
                             turned out the WEEB server uid owned the WEEB
                             config file, so you could just changed the run-as
                             user to root and repeat the process and you would
                             have a root shell on the name server. this is
                             detailed in some comment by myself and P. Norby
                             some time ago. I dont think this is that big a
                             deal and right now the "real" denial of service
                             is all the people running around recommend things
                             like vulnerabilty people immidiately delete their
                             defaultroutes and such. --psb
2025/05/24 [General] UID:1000 Activity:popular
5/24    

You may also be interested in these entries...
2012/8/26-11/7 [Computer/SW/Security] UID:54465 Activity:nil
8/26    Poll: how many of you pub/priv key users: 1) use private keys that
        are not password protected 2) password protect your private keys
        but don't use ssh-agent 3) use ssh-agent:
        1) .
        2) ..
        3) ...
	...
2012/9/20-11/7 [Computer/SW/Unix, Finance/Investment] UID:54482 Activity:nil
9/20    How do I change my shell? chsh says "Cannot change ID to root."
        \_ /usr/bin/chsh does not have the SUID permission set. Without
           being set, it does not successfully change a user's shell.
           Typical newbie sys admin (on soda)
           \_ Actually, it does: -rwsr-xr-x 1 root root 37552 Feb 15  2011 /usr/bin/chsh
	...
2012/8/7-10/17 [Computer/SW/Security] UID:54455 Activity:nil
8/6     Amazon and Apple have lame security policies:
        http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all
        "First you call Amazon and tell them you are the account holder, and
         want to add a credit card number to the account. All you need is the
         name on the account, an associated e-mail address, and the billing
         address. "
	...
2012/7/18-8/19 [Health/Men, Computer/SW/Security] UID:54438 Activity:nil
7/18    "Largest penis record holder arouses security suspicions at airport"
        http://www.csua.org/u/x2f (in.news.yahoo.com)
        \_ I often have that same problem.
        \_ I think the headline writer had some fun with that one.
           \_ One time when I glanced over a Yahoo News headline "U.S. busts
              largest-ever identity theft ring" all I saw was "U.S. busts
	...
2012/5/8-6/4 [Computer/SW/Unix] UID:54383 Activity:nil
5/8     Hello everyone!  This is Josh Hawn, CSUA Tech VP for Spring 2012.
        About 2 weeks ago, someone brought to my attention that our script
        to periodically merge /etc/motd.public into /etc/motd wasn't
        running.  When I looked into it, the cron daemon was running, but
        there hadn't been any root activity in the log since April 7th.  I
        looked into it for a while, but got lost in other things I was
	...
2010/4/19-5/10 [Computer/SW/Security, Computer/SW/WWW/Server] UID:53791 Activity:nil
4/18    http://Apache.org hacked:
        http://www.theinquirer.net/inquirer/news/1601103/apache-hacked
	...
2010/4/22-5/10 [Computer/SW/Languages/Misc] UID:53797 Activity:nil
4/22    In Linux is there an easy way to rename the scripts in /etc/rc?.d ?
        For example I want to set all the /etc/rc?.d/S91apache to S100apache
        so that it'll run the ramdisk BEFORE going to apache.
        \_ Sure, just move them.
           \_ I mean is there a script that will rename all of them
              for me? Like: setrc apache2 0 0 1 1 1 1
	...
2010/1/22-30 [Computer/HW/Laptop, Computer/SW/OS/OsX] UID:53655 Activity:high
1/22    looking to buy a new development laptop
        needs ssdrive, >6 hr possible batt life, and runs linux reasonably
        Anyone have a recommendation? Thx.
        \_ thinkpad t23 w ssdrive and battery inplace of drive bay
        \_ Ever wondered what RICHARD STALLMAN uses for a laptop?  Well,
           wonder no more!
	...
2010/1/12-29 [Computer/SW/Apps/Media] UID:53627 Activity:kinda low
1/12    How do I get a job NOT related to internet DNS social network cloud
        twitter GOOG EC2 amazon API ???
        \_ A CS job not related to API?
        \_ Chip design, or maybe software that does chip design. What is
           your major? How about game developer?
        \_ DNS? DNS? What era ado you live in? I agree that social network
	...
2009/12/7-2010/1/3 [Computer/HW/Memory, Computer/HW] UID:53574 Activity:nil
12/7    How many TCP retransmits are too many? Here is what I get:
            3594143433 segments received
            3760174421 segments send out
            3801829561 segments retransmited
        \_ rephrase. you can never have too much money. or too little.
           what is, is.
	...
2009/5/7-14 [Computer/SW/WWW/Server] UID:52963 Activity:nil
5/7     I am trying to reproduce a customer bug where their apache header
        has the content-encoding as the last line in the header.
        My test platform is running apache2.2 on ubuntu. Is there a way
        to do this ?i I have already read the apache 2.0 docs and
        I dont see anything obvious ? page is txt/html
	...
2009/3/8-17 [Computer/SW/Unix] UID:52685 Activity:kinda low
3/8     I'm reading about an old exploit where someone used a buffer overflow
        in a printer daemon to get "daemon privileges," which allowed them
        to use another exploit on the mail delivery program to get root.  I'm
        not sure what daemon privileges are.  Is there some set of priveleges
        that most daemons run on that is higher than user but lower than root?
        What are they?  I've never heard this before.
	...
2008/10/14-20 [Computer/SW/Languages/Misc, Computer/SW/Languages/Web] UID:51527 Activity:nil
10/14   2 apache 2.0.52 servers running on Linux boxes.  Identical httpd.conf
        files (except for ServerName).  But on one, if a CGI script takes
        longer than 300 seconds, it times out.  The other, not.  Why is that?
        \_ Perhaps network equipment configuration. Or try comparing settings
           in /proc/sys/net.
           \_ I ran /sbin/sysctl -a | grep tcp, all settings are the same.
	...
2008/9/3 [Computer/SW/Unix] UID:51030 Activity:nil
9/3     Okay, my sed and awk skills are obviously not up to par here.
        I want to only see the "500's" in my apache error log, how do I
        do that? I want to see the whole line, not just the 500 error code.
        Never mind, grep " 500 " is close enough.
	...
2008/3/10-13 [Computer/SW/SpamAssassin] UID:49412 Activity:nil
3/10    Is there a reliable way to control spam on soda?
        Can someone write an "any undergrad can do it" level FAQ?  Thanks.
        \_ echo "/dev/null" > ~/.forward
        \_ I use Thunderbird to check my soda mail.
        \_ Forward to gmail.  Let google's spam filter work for you.
        \_ I use spamassassin. I just checked and it caught all but one of
	...
2007/12/11-14 [Computer/SW/OS/Linux, Computer/SW/WWW/Server] UID:48785 Activity:nil
12/11   Apache/Linux question: I've got apache 2.0.52 on an idle redhat
        box (2.6.9-55 kernel).  Every so often one to four apache procs
        will run the cpu at 100% for any where from 15 to 90 mins, then
        drop back to normal.  USR and SYS time both increase to levels
        that the production boxes don't reach when serving traffic at
        noon.  I've checked apache and linux kernel versions, several
	...
Cache (1423 bytes)
apache.org
The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. Software Patents Kill Innovation We are protesting against attempts to legalise software patents in Europe. For ASF developers and users alike, this directive would mean legal uncertainty: a patent minefield. HTTP Server has been the leading web server platform since 1996. Founded as a collaborative effort aimed at creating a robust, commercial grade, standards-compliant, and feature-rich HTTP server, we are thrilled that the worldwide Internet community has embraced open source as a viable model for software product development. Our achievement is testament to the benefits of the process of open source software development itself. Maven is a Java project management and project comprehension tool. In a nutshell Maven aims to make the developer's life easier by providing a well defined project structure, well defined development processes to follow, and a coherent body of documentation that keeps your developers and clients apprised of what's happening with your project.