Re: slapper countermeasures

2002-09-17 Thread KevinL
On Wed, 2002-09-18 at 06:05, Michael Renzmann wrote: killall .bugtraq would be suitable as well, and it would destroy every other instance of the program that is running currently. Even if detecting the current PPID does not work for whatever reason. *chuckle* Solaris is vulnerable to this

Re: slapper countermeasures

2002-09-17 Thread KevinL
On Wed, 2002-09-18 at 06:05, Michael Renzmann wrote: killall .bugtraq would be suitable as well, and it would destroy every other instance of the program that is running currently. Even if detecting the current PPID does not work for whatever reason. *chuckle* Solaris is vulnerable to this

Re: Apache chunk handling vulnerability and Apache 1.3.24-3

2002-06-23 Thread KevinL
Can someone clarify for me, please (not directly debian related, I know, but...) - the patches appear to only be to the chunk-encoding functions in mod_proxy. If mod_proxy isn't loaded, is apache still vulnerable? KJL On Thu, 2002-06-20 at 20:30, Paul Hosking wrote: On Wed, 2002-06-19 at