North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: What HTTP exploit?

  • From: Bob Martin
  • Date: Mon May 31 12:49:45 2004

The real irony is that it doesn't bother Apache running on NT :)

In all fairness, somewhere along the line there was a patch for this. All my Apache servers do is put "request failed: URI too long" in the error log. Even without the fix it really wasn't anything more than a nuisance. Killing off one child process had no effect on valid sessions or the parent process.

Bob Martin

Mike Nice wrote:
It seems to be another stupid Microsoft Exploit that just
causes annoyance for Unix Boxes.
The only side effect is they fill my dmesg logs with
signal 11's from apache crashing.
    
   Am I the only one that sees the irony that Apache seg faults from an
attack aimed at Msoft?!