Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: Apache HTTP Server mod_proxy reverse proxy issue - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Apache HTTP Server mod_proxy reverse proxy issue

The reverse proxy feature (mod_proxy) has a new vulnerability.  If pattern matching is used, a crafted attack (using invalid inputs - even though this does not involve SQL the "Little Bobby Tables" XKCD comes to mind again, for like the 3rd time this week ! ) can expose information on internal hosts.

Full details (and remediation) here ==>

Patch is available for 2.2.21 here==>

the CVE is pretty sparse, but look for more content soon ==> CVE-2011-3368

Rob VandenBrink

Rob VandenBrink

578 Posts
ISC Handler
Oct 6th 2011

Sign Up for Free or Log In to start participating in the conversation!