Slashdot Mirror


OS X Security Update: Apache, SSL and SSH

payote writes "Security Update July 2002 includes the updated components, Apache v1.3.26, mod_ssl v2.8.9 and OpenSSH v3.4p1, which provide increased security to prevent unauthorized access to applications, servers, and the operating system." It's not in my Software Update window, because I'm still on 10.1.4 (having heard rumors that RtCW doesn't work on 10.1.5). But it is indeed out, and any Mac OS X machine whose webserver or ssh server is open to an untrusted network needs to upgrade.

7 of 216 comments (clear)

  1. Whew by sheepab · · Score: 5, Funny

    RedHat just came out with their updated RPMS also. Last time that SSH came out with a security vulnerability (the same time the zlib one hit) I WAS HACKED! Do you know how bad you feel after you've been hacked? Its like being neutered.

    1. Re:Whew by MisterBlister · · Score: 5, Funny
      Do you know how bad you feel after you've been hacked? Its like being neutered.

      You must have been neutered, right? To make that comparison?

      Wow man, you must have big balls to admit in a public forum that you've been neutered. Wait, strike that...

  2. Re:FYI, no reboot needed by MisterBlister · · Score: 2, Funny
    Nicely enough, this does not require a reboot to get working.

    Why should it?

    Upgrading Apache and OpenSSH (and most other apps, even daemons/services) doesn't even require a reboot on Win2000/XP. Welcome to the future!

  3. Re:FYI, no reboot needed by marmoset · · Score: 3, Funny
    He's probably referring to the OS X Networking Update last week that some people bitched about because it forced a reboot. That one required a reboot because it replaced the network stack, not just a few daemons.



    Apple tends to err on the side of caution with their Software Update scripts, usually forcing a reboot.
    I don't mind myself, not being one of those people who equates uptime with anatomical endowment.

  4. Re:FYI, no reboot needed by usr122122121 · · Score: 1, Funny
    I don't mind myself, not being one of those people who equates uptime with anatomical endowment.
    Geez! Didn't you read the FAQ?
    Uptime+Karma^2=Anatomical Endowment
    People these days...
    --

    -braxton
  5. Re:Let's hope Apple gets quicker.... by daeley · · Score: 4, Funny

    They spend hours--nay--days getting their virtual desktop decorated just right.

    We have to have *something* to do when we're not rebooting after crashing, reinstalling the entire system thanks to yet another virus attack, or beating back the EULA police.. That's the kind of substance I can do without, thank you very much.

    Boy, the trolls sure do come out of the woodwork on Apple stories, don't they?

    --
    I watched C-beams glitter in the dark near the Tannhauser gate.
  6. Re:Problem seen - addressed by Anonymous Coward · · Score: 1, Funny

    /etc/init.d/apache stop ... 10 days later ... /etc/init.d/apache start