Apache 2.0.48 Released
Gruturo writes "Busy week for the Apache software foundation:
After 1.3.29, version 2 gets an update as well with 2.0.48, which mainly fixes these two security vulnerabilities.
As usual, using a mirror is recommended." The official announcement lists several changes as well.
And my server is safe, secure and can take a slashdotting.
This shows that there are some 3l337 haxors on the reservations.
http://www.cgisecurity.com/webservers/apache/
go tell them off, at least it'll make you feel better and embarass them.
tell him congratualations on the new STD... that'll make for an interesting night...
Tell me: For how long has Tomcat been an commercial application server?
Yea, I know.. ihbt..
Generally RedHat will not put in new packages at the last minute. But this is a security fix release only and also Fedora is considered more experimental than regular Redhat releases.
Maybe Debian Stable can finally update their Apache packages??? I'm still running 1.3.26... jeez!
I saw this post a couple of weeks back.
Be original, create your own trolls.
It will take all November to compile it :(
An Apache point release on the front page? Can you say "slow news day"?
It's hard to be religious when certain people are never incinerated by bolts of lightning.
This is the funniest pseudo-product placement troll I've ever read. Congrats.
2) Ever heard of Mono? Didn't think so ...
commercial application servers such as Tomcat
.NET framework for Solaris
.NET Framework, not Ximian, although Ximian does have a hand in Mono, the open source implementation of the .NET Framework.
Tomcat is open source; it's one of the Jakarta projects.
compared to Oracle's WebSphere
IBM make WebSphere, not Oracle.
If Ximian would only release the
Microsoft makes the
It's official. Most of you are morons.
WebSphere is IBM, not Oracle.
.NET Framework is Microsoft.
Tomcat is Apache Foundation and Free(tm).
LocalDirector is Cisco.
Besides those minor error and the jibberish the +1 Interesting might be sensible?
2.0.48 is released!
This is the defining moment of my life. I have been continually pressing the "refresh" button since the story about 2.0.47 being released. Now all my hard work has paid off.
2.0.48 is released at last!
... so I can see, the Knicks play basketball.
I used Apache 2.0.47 for all of a day before I decided to never use the 2.0.x line again. Apparently when a partial transfer is requested, Apache 2.0.47 logs the full amount requested. Not what was actually transfered. I ended up showing over 10GB of transfer in a single day on a 256Kbit DSL line. Which if you do the math is only physically capable of about 2.5GB a day.
I looked at my logs and determined that a couple AOL users were trying to get a rather large file
aca9bd40.ipt.aol.com 655 6689 1004 310
acc4e74f.ipt.aol.com 1014 5412 521 148
ac8bd972.ipt.aol.com 140 1565 534 745
Requests MB KB Bytes. All that transfer supposedly happened in about a day.
I notified bug-track but apparently such a simple problem (which doesn't exist in the 1.3.x line) isn't worth addressing.
After all, who actually uses the Apache 2.0.x logs to monitor transfer? Hopefully not any hosting companies because the customers are going to get royally screwed.
Ben
Work Safe Porn
Twice. Software that works means it is right, THE FIRST TIME. If this had been MS, you know damn well you'd be all over them for 'buggy' stuff.
All this proves is OSS zealots are hypocrites, with double standards.
How do you keep an idiot occupied for hours?
Just thought i'd say - the link is a logout link
It sounds like you've got a lot of $1499 licensing fees to pay, you cock-smoking teabagger.
10 bucks says my university still doesn't upgrade it's servers from 2.0.40
How?
You don't pay for the oxygen you're breathing, do you?
Do you know if they released 2.0.48 yet?
the new netcraft stats are posted.
apache just keeps stealing more market share-
It's too bad Fedora will not be coming out on Monday.
sorry don't have time to answer - must test if it is working
Yah, as if anyone's going to let you take a lighter to their cock...sheesh...
Stop the fucking SCO jokes!!! It's over.
We're only gonna die from our own arrogance, that's why we might as well take our time...
nice effort
unfortunatly you are dealing with greasy spotty fatso's here who don't know about sex (except with themselves) but they do know about IT products, maybe you would be better off at Yahoo or MSN forums, they like someone experienced
I disagree. That greasy fatsos know nothing.
too late, redundant
ISA Server
/wierd/ that the httpd team would shoot for functionality with another product from the Apache
.NET framework for Solaris we would definately be able to unleash some more serious functionality
huh? Microsoft Internet Security and Acceleration Server? The one all the dweebs put in front of Exchange when management's looking the other way? That's not an application server, it's a proxy/firewall whose chief function is to generate revenue for Microsoft while providing zero real functionality.
the Apache team outdid themselves by providing a nice API that integrates nicely with most the commercial application servers such as Tomcat...
How
Group..
DBAs find the performance lacking compared to Oracle's WebSphere
And they are right: Oracle's Websphere is pretty slow - it doesn't freekin' exist so it doesn't run very fast AT ALL.
If Ximian would only release the
Looks like you and the team switch development and delivery platforms every 7 to 10 days. It seems like those Ximian people go out of their way to slow progress. BASTARDS!
definately
Most everyone is definitely using a more recent version of definitely, which is nice. You can download it at www.m-w.com on the Internet.
IT's OVER?
WTF do you mean? It sure as hell looks like their stock price is going up to me? It sure as hell looks like they have other corporate idiot assholes convinced?
It's OVER? You're a fucking idiot! They hase OSS over a barrel!
proof
The quality of both the mods and /. itself continues its downhill slide. And it is piciking up pace!
Thank you. I've used up my mod-points.
If the fixes were from Microsoft, the /. would have an article "Two More Critical Windows Flaws".
But it is open source, so we get "Apache 2.0.48 Released".
So does it proof anything except double standard on /.?
MSDOS: 20+ years without remote hole in the default install
I just made simple statement that indicated that the original post reflects the sad state of affairs of /. and its moderation system. If you look at my low UID you'll see I've been around here for years so I think I have to right to speak my mind.
For the pollyannish ...
e dule/
From:
http://fedora.redhat.com/participate/sch
Schedule
Fedora Core 1 / Cambridge
* July 21 2003 - Test 1 (originally called Beta 1) release
* September 25 2003 - Test 2 release
* October 13 2003 - Test 3 release
* November 3 2003 - General Availability
Should I upgrade?
Or should I hold out for 2.0.49?
sorry to burst your bubble, but...
If you're going to flame someone's spelling, at least take the time to get your own spelling right. It's "weird."
Are people using 2.0 much yet? I remember all of the blowup over how 2.0 didn't really add anything unless you wanted to run it on Windows, and it caused a lot of problems for modules like mod_perl. Is everyone still sticking with 1.3?
See this.
This version was released the same day as 1.3.29 earlier in the week, Wednesday, I believe. Perhaps future posters would consider combining this news into one post.
When trying to get your software announced on freshmeat.net, has anyone else got pissed off with how long it takes the editors to post your announcement on the front page.
When it does finally appear, it appears in the same batch as hundereds of other announcements and goes off the front page straight away. Grr...
Why are there two branches of Apache? There's the 1.3 and 2.0 lines. I've heard that 1.3 is better than 2.0, so is 2.0 effectivelly a beta? Why are there still new releases of 1.3, why not concentrate on 2.0?
I didn't know "open source" contrasted with "commercial."
> We had to respin FC1 today for a non-technical issue
What the heck is "respin" ?
Apache 2.0.48 works extremely well on windows 2000 there are no problems such as hanging during shutdown for me anymore one qualm i have is that the configuration could be made a bit easier using a web based interface like the one which abyss web server from www.aprelium.com has i look forward to a long and happy life with apache MC
The "Monitor Apache Servers" program seems to have a weird effect on the windows API when it is visible for example copy and paste wont work very well if at all, minimizing the window fixes the problem very weird all in all a better apache
Dude, what are you waiting for? Go in there and hook up some fingercuffs / DP action.
That fix should be standard. Obviously Apache knows about the problem but even when someone fixes it for them (so writting a fix myself as someone else suggested is a worthless pursuit to try to actually fix the problem) they continue to insist on ignoring the problem and linking by default to a known broken module that they refuse to fix. And on top of that, they fail to properly document the workaround.
Most web-site owners are more interested in running their business than dicking around with source code. Even if they knew how to even begin looking for the problem spot. I opted to revert back to 1.3.x since it's solid.
This reflects very poorly on Apache in regards to their attitude about bugs. Especially considering this shouldn't have been broken from the first 2.0 release.
"We know about it, but we don't care to fix our default logging module" is pretty sad.
It's nice to know a workaround exists but when something as simple as logging can't get an official fix it does very little to instill confidence in the product.
Maybe I'll give 2.0 another try later with my personal server but the server my business runs on will be sticking with 1.3. It works great and so I can just focus on running the business and writting source code for a job instead of reinventing fixes for a wheel that's been known to be broken for a very long time.
Ben
Work Safe Porn
Doesn't go over well with business people. I do programming as a profession. However, when the 1.3.x line is flawless it's hard to convince myself it's worth my time to tackle this problem. Considering how many people have downloaded and rely on the 2.0 line, I wonder how many have the skill or motivation to fix such a glaring and simplistic flaw that should never have existed.
Especially considering someone did take the time to write a logging module that works and Apache still refuses to make it the standard, insisting instead to link to the default, "approved," known to be broken one.
By telling me to "fix it myself" he was basically telling everyone to ignore the fact that Apache is ignoring already existing fixes and needlessly reinvent the wheel themselves.
I'd actually be happier not knowing the fix existed. Apache's actions would make more sense (and be more acceptible) because I could pretend it was a complicated issue still in progress.
Ben
Work Safe Porn
I do programming as a profession
Oooh. Am I supposed to bow to your mightiness? Frankly, you've already swept me off my feet.
By telling me to "fix it myself" he was basically telling everyone to ignore the fact that Apache is ignoring already existing fixes and needlessly reinvent the wheel themselves.
No, actually, he was basically telling you to fix it yourself, no need to read into it. If you're such a programming professional, it should be trivial to fix. Apache isn't someone you pay for something to work. It, like all other OSS projects, only get better when people get off their butt and fix problems. However, I'd rather have it stay broken and get fixed by someone decent than for it to grudgingly get fixed by as it's obvious you are a leech on open source's inner thigh.
How is this flamebait? Seriously, if what this poor bloke says is true, then his roommate deserves at least *one million* punches-in-the-face.
(link for the humour impaired)
Duct tape, XML, democracy: Not doing the job? Use more.
When Windows Service Packs come out, you get a "Windows Service Pack released" header.
Do you read the responses before making your own? YOU HAVE CONTRIBUTED NOTHING. Good show.
If the Apache team wants everyone to adopt 2.x, they better make sure it works flawlessly. Or at least as good as the 1.x line. I agree with Ben, and I'm not the only one (a lot of admins still like 1.x better) and I'm not upgrading until all the shit works right. Production sites should only run the most stable and bug-free code, and that means 1.x for now and maybe quite some time into the future if what Ben described was true (the part about the Apache developers not caring enough to use a working subsystem instead of the standard, but broken version).
Saving lots of memory: Just run in 'worker' mode, and have only one system wide Python Interpreter. Also makes sharing DB connections and so much easier since you can just keep lots of globals around.
And that's on Solaris, where worker isn't default.
Oh, and mod_deflate is nice too.
Musicians don't die. They just decompose.