Nmap Development mailing list archives

Re: Apache killer 3192


From: John Bond <john.r.bond () gmail com>
Date: Mon, 12 Sep 2011 19:57:08 +0200

On 12 September 2011 19:46, Henri Doreau <henri.doreau () greenbone net> wrote:
2011/9/12 Adrian Coelho <adrian.coelho () gmail com>:
NSE: http-vuln-cve2011-3192: Functionality check HEAD request failed for
x.x.x.x (with path '/').

I can't trigger any problem with the script. Is your server configured
to accept HEAD requests on port 443?
Adrian,

What do you get id you do a head request using openssl

run
openssl s_client -connect server:443

then type
HEAD / HTTP/1.0
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: