+ Reply to Thread
Results 1 to 6 of 6




  

Thread: Apache mod_ssl vulnerability and mitigation

      
  1. #1
    Grand Masters vectro is just really nicevectro is just really nicevectro is just really nicevectro is just really nicevectro is just really nicevectro is just really nicevectro is just really nicevectro is just really nice vectro's Avatar
    Join Date
    September 5, 2008
    Location
    U.S.A.
    Posts
    1,499
    Rep Power
    4
    Feedback Score
    0

    Default Apache mod_ssl vulnerability and mitigation

    Apache httpd is affected by CVE-2009-3555[1] (The SSL Injection
    or MiM attack[2]).

    The Apache httpd webserver relies on OpenSSL for the implementation of
    the SSL/TLS protocol.

    We strongly urge you to upgrade to OpenSSL 0.9.8l; and to be prepared
    to deploy OpenSSL 0.9.8m as it becomes available[3].

    Note that these are for short term and mid-term mitigation only; the
    long term solution may well require a modification of the SSL and/or
    TLS protocols[4].

    For those who are not able to upgrade OpenSSL swiftly and/or for
    those who need detailed logging - we recommend that you roll out
    this patch[5]:

    Index of /dist/httpd/patches
    apply_to_2.2.14 CVE-2009-3555-2.2.patch
    sha1: 28cd58f3758f1add39417333825b9d854f4f5f43

    as soon as possible. This is a partial fix in lieu of the protocol
    issues being addressed and further changes to OpenSSL. Like the
    OpenSSL 0.9.8l stopgap measure this patch rejects
    in-session renegotiation.

    If you are unable to patch and unable to roll our a newer version of
    OpenSSL, and you rely on Client Side Authentication with Certificates
    then we recommend that you 1) ensure that you limit your configuration
    to a single 'SSLClient require' on VirtualHost/Sever level and 2)
    remove all other (re)negotiation/require directives. However this does
    NOT fully protect you - it just curtails authentication in this
    specific setting.



    1: http://cve.mitre.org/cgi-bin/cvename...=CVE-2009-3555
    2: Links » Another Protocol Bites The Dust, extendedsubset.com
    3: OpenSSL: Source, Tarballs
    openssl-announce mailing list on
    OpenSSL: Support, Mailing Lists
    4: Re: [TLS] TLS renegotiation issue
    5: svn diff -r833581:833594 https://svn.apache.org/repos/asf/
    httpd/httpd/trunk/modules/ssl
    Vectro Web Hosting - Web hosting with solid tech support.

    x Proxy Host - Affordable PHP proxy hosting with proxy-specific features.

  2. #2
    I'm New! Danielad is on a distinguished road
    Join Date
    November 14, 2009
    Posts
    6
    Rep Power
    0
    Feedback Score
    0

    Default Website design

    Hi,
    I have a great information for you to desing your website, go through this site Affordable Web Hosting,its great and provides Affordable Web Hosting,Be safe!

  3. #3
    I'm New! Danielad is on a distinguished road
    Join Date
    November 14, 2009
    Posts
    6
    Rep Power
    0
    Feedback Score
    0

    Post michigan website design

    I have a great news for you,go through this site michigan website design, it provides web hosting with affordable prize,try this one!

  4. #4
    I'm New! Danielad is on a distinguished road
    Join Date
    November 14, 2009
    Posts
    6
    Rep Power
    0
    Feedback Score
    0

    Default Re: Website design

    I have a great information for you to design

  5. #5
    I'm New! Danielad is on a distinguished road
    Join Date
    November 14, 2009
    Posts
    6
    Rep Power
    0
    Feedback Score
    0

    Default Website design

    Hi,
    I have a great information for you to desing your website, go through this site michigan website design,its great and provides Affordable Web Hosting,Be safe!

  6. #6
    I'm New! Danielad is on a distinguished road
    Join Date
    November 14, 2009
    Posts
    6
    Rep Power
    0
    Feedback Score
    0

    Default Website design

    [QUOTE=Danielad;285583]Hi,
    I have a great information for you to desing your website, go through this site michigan website design,its great and provides Affordable Web Hosting,Be safe

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Prevent Apache and PHP from displaying too much information
    By vectro in forum Dedicated / VPS Hosting
    Replies: 8
    Last Post: Oct 3rd, 2009, 11:34 am
  2. New version of Apache web server released
    By vectro in forum Dedicated / VPS Hosting
    Replies: 2
    Last Post: Aug 28th, 2009, 3:58 pm
  3. Apache Editing? WTFFF.
    By unr in forum Programming
    Replies: 6
    Last Post: May 13th, 2008, 5:13 pm
  4. cPanel never updates FPE and mod_ssl?
    By Izzmo in forum Dedicated / VPS Hosting
    Replies: 6
    Last Post: Mar 14th, 2008, 11:29 am

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
WebTalkForums
WebTalkForums
Recent Forum Threads