Bugtraq mailing list archives
Re: Apache worm in the wild
From: Brett Glass <brett () lariat org>
Date: Fri, 28 Jun 2002 11:27:13 -0600
At 05:38 AM 6/28/2002, flynn () energyhq homeip net wrote:
I wonder how many variants of this kind of thing we'll see, but I assume most people running Apache have upgraded already.
Upgrading Apache may prevent your system from being taken over, but it doesn't necessarily prevent it from being DoSed. One of my Apache servers, which had been upgraded to 2.0.39, went berserk on June 25th, spawning the maximum number of child processes and then locking up. The server did not appear to have been infiltrated, but the logs were filled with megabytes of messages indicating that the child processes were repeatedly trying to free chunks of memory that were already free. Probably the result of an attempted exploit going awry. (It could have been aimed at Linux, or at a different version of Apache; can't tell. But clearly it got somewhere, though not all the way.) --Brett
Current thread:
- Apache worm in the wild Domas Mituzas (Jun 28)
- Re: Apache worm in the wild flynn (Jun 28)
- Re: Apache worm in the wild Brett Glass (Jun 28)
- Re: Apache worm in the wild Mihai (Cop) Moldovanu (Jun 28)
- Re: Apache worm in the wild wink (Jun 28)
- Re: Apache worm in the wild flynn (Jun 28)