|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 | ||
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
The killapache.pl launches in a few threads the following simple request:
Quote:
![]() Here is a simple command to check if your server is vulnerable: Quote:
__________________
Obey the Cowgod |
||
|
|
|
|
|
#2 |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
__________________
Obey the Cowgod |
|
|
|
|
|
#3 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Looks like many of mine are vulnerable. On my dev server I get the message "Host does not seem vulnerable" after disabling mod_deflate.
Edit: nevermind...looks like a fluke. Still vulnerable. |
|
|
|
|
|
#4 |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
What is this "apache" you speaking of
![]() |
|
|
|
|
|
#5 |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
__________________
Obey the Cowgod |
|
|
|
|
|
#6 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Haha just crashed my dev server with the tool.
![]() |
|
|
|
|
|
#7 |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
|
|
|
|
|
#8 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
|
|
|
|
|
|
#9 |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
|
|
|
|
|
#10 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
|
|
|
|
|
|
#11 |
|
making it rain
Industry Role:
Join Date: Oct 2003
Location: seattle
Posts: 22,130
|
Workaround:
Code:
RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^(HEAD|GET) [NC]
RewriteCond %{HTTP:Range} ([0-9]*-[0-9]*)(\s*,\s*[0-9]*-[0-9]*)+
RewriteRule .* - [F]
|
|
|
|
|
|
#12 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
|
|
|
|
|
|
#13 |
|
making it rain
Industry Role:
Join Date: Oct 2003
Location: seattle
Posts: 22,130
|
|
|
|
|
|
|
#14 | |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Quote:
![]() This hack freaks me out. This is the first one I have been vulnerable to EVER. |
|
|
|
|
|
|
#15 | |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
![]() |
|
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
A working patch is already available, though it will be improved in the next few days.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
|
|
|
|
|
#17 |
|
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
I gotta chuckle at the nginx fanboy who's never heard of noatime using this to pitch nginx.
It's a little like suggesting that people avoid the latest Vista bug by running Windows 95, isn't it.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
|
|
|
|
|
#18 |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
Not at all. The wise ppl. using Apache as a main server. nginx should be used for static content only.
__________________
Obey the Cowgod |
|
|
|
|
|
#19 |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
It is common recommendation,but there is simply no need for it since nginx can do almost anything what apache do,including CGI.Plus it do even some non-optimization related things better then apache.
|
|
|
|
|
|
#20 |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Just for the record,i using noatime along with nginx plus many other optimization methods for which you clueless noob probably never heard.
|
|
|
|
|
|
#21 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Why do you think you need nginx?
__________________
I like pie. |
|
|
|
|
|
#22 |
|
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
It's simply my personal choice,and also way way easier to manage then apache.While you can by stripping apache modules and it's configuration reduce load,on nginx it's enough to install it and it already work better then optimized apache,not the mention you can optimize it further then too.I mean seriously,why i would bother with apache if on nginx i have everything what i need,everything works there and never having any problem unlike on apache which was constant issue till i went to nginx before 4 years.Also,currently nginx is not champion when it comes to load optimization there is one even better solution but for my traffic levels nginx do the job.
|
|
|
|
|
|
#24 |
|
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Digging through the nginx code and testing, I found the apparent advantage for nginx was simply that it basically forces noatime as one of it's bugs.
iIn our testing, Apache beats nginx + Apache as long as you use noatime. Just as you'd expect from profiling either, the time is spent on io, so Apache by itself is just as fast as nginx by itself. Neither can magically make the disks faster. Alternatively, if you don't want noatime, nginx is a non-starter because it skips atime updates whether you like it or not. |
|
|
|