OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Matthew S. Hallacy (poptixtechmonkeys.org)
Date: Mon Sep 10 2001 - 20:05:10 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    howdy,

    We had YASK (yet another script kiddie) join #linux on efnet tonight asking for a patch for the new
    apache exploit, knowing of no recent exploit I convinced him to try it on my machine, he claimed
    all he had was a binary compiled to only work on his machine (possible). He tried it and messaged
    me this:

     [roothisbox /]# ./apex x.x.x.x
     -= FtSoK 0wnz =-
     Checking daemon version...: Apache/1.3.19 (Unix)
     Attempting to compromise..: x.x.x.x
     Remote system is..........: Linux. (Red-Hat/Linux)
     Connected! ...but not vulnerable.

    Where x.x.x.x is the address of my machine, I was packet logging (tcpdump) but came up with nothing
    out of the ordinary, perhaps someone else knows more.

                                            Matthew S. Hallacy

    -- 
    --