RE: [SLUG] apache proxy exploit?

From: Russ Wright (rwrigh10@tampabay.rr.com)
Date: Wed Apr 28 2004 - 07:55:36 EDT


Steve Wrote:

><Limit GET POST OPTIONS HEAD>
>Order allow,deny
>Allow from all
></Limit>
><LimitExcept GET POST OPTIONS HEAD>
>Order deny,allow
>Deny from all
></LimitExcept>

Excellent! But is there a particular place in httpd.conf that I must place
this info or can I just put it right at the top?

>To test it telnet to <ip> 80

Will do

>Now I would run a port scan, on your machine, as many backorifice and
>subseven servers use that address/port combo.

I tried this using nmap and all that is open is 21(ftp) ,80 (http) and 5901
(vncserver)

-----------------------------------------------------------------------
This list is provided as an unmoderated internet service by Networked
Knowledge Systems (NKS). Views and opinions expressed in messages
posted are those of the author and do not necessarily reflect the
official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 16:59:20 EDT