Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Gobbles Releases Apache Exploit
Brian McWilliams, SecurityFocus 2002-06-20

Tool makes it easy to hack vulnerable Apache servers under OpenBSD.

Comments Mode:
Gobbles Releases Apache Exploit 2002-06-20
Anonymous (1 replies)
Gobbles Releases Apache Exploit 2002-06-24
Anonymous
Hackers 2002-06-20
Anonymous (2 replies)
Hackers 2002-06-20
Anonymous2
Hackers 2002-06-21
The Clone (7 replies)
Hackers 2002-06-21
Anonymous (2 replies)
Hackers 2002-06-24
Anonymous Cowardess
Hackers-GO 2002-06-24
omikorn (at) yahoo (dot) com [email concealed] (1 replies)
Re: Hackers-GO 2005-10-26
a Nocturnal student
Hackers 2002-06-21
paralyse
Hackers 2002-06-21
Anonymous (1 replies)
Hackers 2002-06-22
Anonymous
Hackers 2002-06-21
Not Really Anonymous
Hackers 2002-06-21
Anonymous
Hackers 2002-06-21
Anonymous
Hackers 2002-06-25
Anonymous
eEye Scanner 2002-06-21
Dirk (1 replies)
eEye Scanner 2002-06-21
marc (1 replies)
eEye Scanner 2002-06-21
lord aambro (1 replies)
eEye Scanner 2002-06-23
Anonymous (1 replies)
eEye Scanner 2002-06-24
Anonymous
Gobbles Releases Apache Exploit 2002-06-21
nologin (1 replies)
Exploit Attemped on FreeBSD 2002-06-24
Anonymous
Gobbles Releases Apache Exploit 2002-06-21
<bangular (at) linuxmail (dot) org [email concealed]>
Gobbles Releases Apache Exploit 2002-06-21
Anonymous
Gobbles Releases Apache Exploit 2002-06-21
Anonymous
Gobbles on time 2002-06-21
Anonymous (4 replies)
Gobbles on time 2002-06-21
The Clone
Gobbles on time 2002-06-22
Anonymous
Gobbles on time 2002-06-22
Anonymous (4 replies)
Gobbles on time 2002-06-22
Anonymous
Gobbles on time 2002-06-22
Anonymous (1 replies)
Gobbles on time 2002-06-24
Anonymous
Gobbles should do time 2002-06-22
Anonymous (2 replies)
Gobbles should do time 2002-06-24
Anonymous
Gobbles should do time 2002-06-24
Anonymous
Gobbles on time 2002-06-22
Anonymous (1 replies)
Hacking -v- cracking 2002-06-25
Anonymous
Gobbles on time 2002-06-22
Anonymous
Gobbles Releases Apache Exploit 2002-06-23
Anonymous (2 replies)
1)maybe this will encourage openbsd to move to a(n even) stronger position, but it seems to take the "if you enable it you own it" position, but people run services, not just portmap and inetd (with nothing on) and sshd, but stuff like webservers.

2)this attempts to ridicule openbsd as "theobsd" but openbsd is the work of a lot of talented people, so really the snub is at the deprecation of all of their efforts, more than finding one bug in a piece of widely used software

3)I guess monkey.org getting broken into is a good indication that there is something as yet unseen on the security horizon

4)the goal here is to hit the at the rep of openbsd, but the 5 year claim is a silly claim anyway, really showing the difficulty of evaluating how secure software is.

5)there is no proof that prosecuting crackers like gobbles would remove these kinds of tools from many security oriented bug researchers. It would definitely make the process of getting fame for their exploits more hazardous. But if (the/any) criminal justice system really worked, why is there still rampant crime?

6)My guess is that ISS was aware of this exploit in the wild when they decided to "discover it".

7)Maybe the OpenBSD model really isn't paranoid enough.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/493/13203#13203
Gobbles Releases Apache Exploit 2002-06-23
Anon (1 replies)
Gobbles Releases Apache Exploit 2002-06-25
Penile Implant
Gobbles Releases Apache Exploit 2002-06-25
Not Really Anonymous
Gobbles Releases Apache Exploit 2002-06-24
Anonymous Coward (1 replies)







 

Privacy Statement
Copyright 2008, SecurityFocus