Apache 1.3.33 Released
harmgsn writes "Following the release of Apache 1.3.32, the Apache Group released Apache 1.3.33 to fix a security flaw in mod_include and in the Content-Length field. The official announcement is available as well as the ChangeLog for the 1.3.x series."
I just got done upgrading to 1.3.32. Oh well, at least 1.3.37 is nearer.
Another fix for a security flaw in a massively outdated apache. Use Apache 2 by now!
It's a real server!
Will there ever be software released that doesn't have flaws or bugs, or is that just utterly impossible? Even the Mozilla foundation has vulnerability and bug problems, and they have some of the best coders out there.
Free Desk
Been using Apache 2 on Fedora Core for the past few months, so shouldn't have any worries.
Brandon Petersen
Get Firefox!
So, one small change was made to prevent dumbasses from fucking over the buffer if they use characters not intended in the first place? Not worth it without updating other bugs, sorry to say. Work on the more important yet less known bugs instead!
'Yes, firefox is indeed greater than women. Can women block pops up for you? No. Can Firefox show you naked women? Yes.'
Slashdot even has a fucking sidebar for you lazy fuckers who only visit this site and rely on it for everything...why does shit like this make the front page when there is legitimate news to put up?
"News for Nerds" used to exclude meaningless updates to outdated software. Why not just put up the latest Windows Update patches on the front page?
Do people actually pay for this content? Looking at the front page right now, there is a story that has almost nothing but a link and absolutely no explanation of what it's about, a story which can't tell the difference between trademark, copyright, and patent, and a version announcement for the obsolete branch of Apache.
It is now official. Headcraft confirms: *BEHEADING is dying
One more crippling bombshell hit the already beleaguered *BEHEADING community when Headcraft confirmed that the total number of executions by *BEHEADING dropped yet again, now down to less than a fraction of 1 percent of all executions worldwide. Coming on the heels of a recent Headcraft survey which plainly states that *BEHEADING has dropped dramatically after the US invasion of Iraq, this news serves to reinforce what we've known all along. *BEHEADING is collapsing in complete disarray, as fittingly exemplified by failing dead last in the recent Ruthless Dictators comprehensive execution test.
You don't need to be a Jailed Dictator to predict *BEHEADING's future. The hand writing is on the wall: *BEHEADING faces a bleak future. In fact there won't be any future at all for *BEHEADING because *BEHEADING is dying. Things are looking very bad for *BEHEADING. As many of us are already aware, *BEHEADING continues to lose market share. Rivers of blood no longer flow from headless corpses..
Ruthless dictator *BEHEADING is the most endangered of them all, having lost 93% of its core dictators. The sudden and unpleasant deaths of long time *BEHEADING evangelists Uday and Qusay Hussein only serve to underscore the point more clearly. There can no longer be any doubt: *BEHEADING is dying.
Let's keep to the facts and look at the numbers.
*BEHEADING leader Qusay stated that 500,000 Iraqis 'dissappeard' during Saddam's regime. How many of them died by *BEHEADING? Let's see. Executions were generally carried out by hanging, bullet to the head, or *BEHEADING. With *BEHEADING being to most difficult to clean up after, let's conservatively estimate that only 5% of the Iraqis that 'disappeared' were *BEHEADED, so 500,000 / 20 = 25,000 deaths by *BEHEADING during Saddam's regime. Saddam took power in 1979, meaning his regime lasted 24 years. Therefore there were (25,000 / 24) ~ 1041 *BEHEADINGS PER YEAR during Saddam's regime. This is consistent with human rights reports. Since the US invasion, there have been approximately 50 *BEHEADINGS. Therefore there have been (50 / 1.5) ~ 33 *BEHEADINGS PER YEAR after the US invasion. Clearly, the terrorists are not as efficient at *BEHEADING. *BEHEADINGS have dropped 97% in the past 18 months. Clearly *BEHEADING is dying.
Due to the troubles of Saddam's Regime, what with it being gone and everything, massive amounts of *BEHEADING stopped and was taken over by a dismal few but high profile *BEHEADINGs that were carried out by nothing but cowardly terrorists Now *BEHEADING is also dead, its corpse turned over to yet another charnel house.
All major surveys show that *BEHEADING has rapidly declined in market share. *BEHEADING is very sick and its long term survival prospects are very dim. If *BEHEADING is to survive at all it will be among terrorist networks. *BEHEADING continues to decay. Nothing short of a miracle could save it at this point in time. For all practical purposes, *BEHEADING is dying.
Fact: *BEHEADING is dead.
© 2004 CmdrTaco (troll)
I hope high gas prices are depriving your children, you fucking dumbass.
Not to say that justifies it, but this is just one bugfix. I hope people maintaining servers running Apache don't rely on Slashdot to inform them of this bug. This seems more an issue for a mailing list.
I've been expecting this one, and I know it when I see it.
I use debian stable. does this effect me?
seems to only effect people who use the mod include thing, which I have not installed, or I think I haven't. I don't want to loose the security battle over a bug like this, but I don't want to have to uninstall apache either.
But what can be done? It all seems so hopeless. My city, beautiful and coastal, has been colonised by the Chinese. Within 10 years, whites will be a minority. The Chinese do not want to integrate, learn English, or abide by our rules. Now we have gang violence, widespread fraud, illegal animal parts in crazy voodoo medicines, and Chinese people looking down their noses at us "mongrel" whites.
Theoden was right: How did it come to this?
During last years jihad on IIS & IE I decided it would be a good idea to migrate the company's web servers to Apache. I decided to start simple and submit a plan to migrate just the department intranet server.
This is the actual response from management. The brain-dead VP that made this truly-enlightened decision first made a name for himself as a VP at a FAUCET COMPANY.
Listen to the faucet kings great idea:
"Shane, Thanks for your proposal. Unfortunately, I cannot approve the change. In fact, I've decided that we need to streamline these things in the future and make sure everyone is on the same page.
From now on, we will only install software on the servers that is at version 2.0 and above. There will be no exceptions to this. It's about security and reliability. Everyone knows you dont buy a car the first model year, why should software be any different. I've never heard of apachee, but if these guys are as good as you say they are enough people will bite to keep them going, and when they come out with the next major realease I think you'll see then that we're better off for waiting for them to really get it right.
thanks for beging on board with this, tom." [my name's shane]
Two years ago this guy won the "visionary of the year" award at the company conference.
Liberals who embrace sand niggers, chinks, kykes, niggers, AIDS infected slime and fucking dotheads. These fucking liberal scum have fucked america. Its too late, my friend, enjoy its waning days of glory and prepare to fucked by the 3rd world.
what exactly are the great historical accomplishments of "your" race that make you proud to be white?
Capitalism? Slavery? Genocide? Sitcoms? Guns? War? Pollution? Addiction? NAFTA? Thigh-Master?
This is your fucking white-history, my "friend".
So why don't we start making a history worth being proud of and start fighting the real fucking enemy:
What's wrong with capitalism?
Why is your server running 2.0, then?
Netcraft's "What's That Site Running?" report on www.force-elite.com
I'm assuming by your nick here that you're Chip, of course.
Discovery of radio waves. Landing on the moon first. Invention of the transistor. Theory of relativity. Bach, Beethoven, Mozart, Chopin, Liszt, Rachmaninoff, Prokofiev.
White European Men. We did everything.
Trains, planes, cars, rockets, telescopes, tires, telephones, radios, television, electricity, atomic energy, computers, and fax machines. All miracles made possible by the minds and spirits of men with names like Ampere, Bell, Caselli, Edison, Ohm, Faraday, Einstein, Cohen, Teller, Shockley, Hertz, Marconi, Morse, Popov. Ford, Volta, Michelin, Dunlop, Watt, Diesel, Galileo, and other "dead white males."
All reports indicate that we have a booming economy right now, but few understand why this is so. I hate to disappoint my friends on the radical left, but it has nothing to do with Bonnie and Clyde Clinton or the Democratic Party, or with any other party for that matter. What I'm about to say is tantamount to blasphemy in this politically correct day and age; yet truth is truth. How long are we going to pretend that origins play no role in our world, the origins of the inventions, science, technology, and economics of the world in which we live?
Our present economic boom is due to the revolution in electronics and computer technology. But saying this is not enough, for these things didn't just spring into existence by themselves. They have traceable origins. And all of our "booms," throughout history, have the same origins as this one. It's no mystery. Just look at the list of names in your history books, and their national origins.
The great majority of "booms" past and present have been brought about by the genius and inventiveness of that most "despicable" of genders, the dreaded white male, or, to be exact, by specific, individual white males. This is not to discredit the many contributions coming from non-whites, but fact is fact. Our most important and consequential inventions have come almost exclusively from white males.
Curse me, or all white males, if you wish, that changes nothing. But if you call me a liar, you'll have to come up with the proof that I'm wrong. Remember, I didn't say there were no important contributions by non-whites; I said the overwhelming majority. Of course, I know about such things as the Chinese and gunpowder, but they didn't take it much beyond firecrackers and pyrotechnics. And I know about the pyramids and masonry of South America and the zero of the Arabs.
Would we have atomic physics and electricity if it hadn't been for the ancient Greek philosophers who, for example, had the idea that all matter consists of tiny atoms? Aristotle (5th century, B.C., 25th century pre P.C.) used electric charges to treat gout! Archimedes perceived the center of gravity of solids, cylinders, and spheres. From the basic discoveries of Greek civilization it went to the Romans and after the fall of Rome, it passed to later Europeans who expanded on this scientific knowledge. In modern times these ideas were developed by such Europeans as Volta, Ampere, Watts, Bell, Edison, and Einstein, who provided the basis for most of the technical wonders of today. All of them dreaded white males.
Maybe you got your enlightenment from one of the Ivy-League institutions of dis-education. Maybe they taught you that it's all the result of white racism and oppression. That every time a potential Einstein, Edison, or Ford popped up in the Third World, a White hit-squad would swoop down and eliminate him before he had a chance to prove himself. Or maybe their schools refused to teach him in the Ebonics of his day. Or maybe they didn't have proper daycare facilities. Or maybe our would-be innovator came from a "dysfunctional family."
But the facts tell us that many of the great men pursued their genius at great personal risk--like the astronomer Galileo, who proved that the earth revolves around the sun. He and other men of genius and courage refused to be suppressed even if it meant their lives. They would permit no race, gender, group or class to keep them from their pursuit of truth and excellence whatever the cost.
If you eliminate, suppress, or debase the while male, you kill the goose that laid the golden egg. If
I'm sorry, but I run a huge online community (http://www.mma.tv/TUF), and Apache has been nothing but trouble for us. We're having hours of downtime A DAY! and we've done everything: bought a brand new server, increased the number of requests per child, disabled all uneeded services, performance tuned our app, the UnderGroud Forum, but to no avail. Under IIS, we had no such problems (the app is written in Cold Fusion and uses JRun).
It doesn't appear that mod_ssl 1.3.33-NNN is available yet. I can't update until this is done, or all my ssl sites break.
ugh...
and I'd just started rolling out 1.3.32!
I have no problem with your religion until you decide it's reason to deprive others of the truth.
We're almost at version 1.3.37.....
Apache the most robust webserver ever. !
Chris ,
Php Programmers.
what, it would follow 1.3.34?
Do they have to keep releasing a new version everytime a bug or security flaw comes up?
Why not just release patches for the bugs and just update the patch tree??
Lord of the Binges.
That's not what I meant at all. What I meant was by the comment that Knuth is a "freak" that Knuth is a freakishly talented individual. And, yes, Knuth's situation is pretty unique, even for open source developers. Not only does he have tenure (that means they can't sack him), because of his reputation he's able to spend his time doing pretty much whatever he wants to do free of the restrictions on ordinary academics, like that little thing, "teaching", or sweating over whether he's going to get published. So he could hack away at TeX as and when the mood took him, without any pressure from his boss to actually produce anything, or any users badgering him for a new release, or figuring out how the other developers had screwed up, or trying to implement broken bits of the standard (because there *was* no standard).
They are *not* the typical circumstances under which most developers have to work.
Any sufficiently advanced technology is indistinguishable from a rigged demo
--Andy Finkel (J. Klass?)
. . . and speaking of pour websites, one of our old customers (I had to try and answer his question in a professional way as to why people weren't coming to his website) designing-websites.com although he has gotten a lot better than what it was before
> From now on, we will only install software on the servers that is at version 2.0 and above
Hmm.. let this guy install Windows 3.1 on the servers (apparently that *is* > 2.0)
Hmm.. maybe I wonder if Knuth did a good thing by freezing TeX at 3.14 (or was it 3.14.15...)
Quidquid latine dictum sit, altum videtur
ok, for a newbie, what are my options? I'm trying to stick with the apache deb packages so that I can use synaptic to update with, instead of tracking everything manually, which I still can't understand how people can do this.
/. post I mentioned above. Can someone clear up my confusion, should I be looking for a security repository for testing? Is there one for stable, and when sarge goes stable, will I be using a security repository that is separate from the us/non-us/contrib repositories?
I'm using testing in my sources file, hoping to ride sarge into stable. I did an update, and it still shows apache at 1-3-31. I added unstable to the sources file, and it still shows apache at 1-3-31.
So what am I supposed to do, either disable apache, or get the tarballs and compile 1-3-33 myself, and lose the ability to update via apt? Or is there a patch to look for, where I can temporarily patch 1-3-31 until 1-3-33 makes it into testing or unstable?
Also, I saw a post recently where the security repository wasn't set up for testing yet, even though testing was getting the attention of the security team now because it is so close to being stable. In the post, it stated that there was some sort of trouble with the security repository setup.
I assumed that the testing repository themselves were where the security team addressed problems, by bringing out new deb packages of the applications. I'm assuming this is wrong now, because of what I read in the
I've been avoiding exposing a server to the internet for months over this issue. I've been using an appliance firewall to expose port 80 and the ntp port only, and blocking all other ports, since I'm having trouble with iptables, and don't want to expose a service due to the security issue above. I've taken some steps to harden the server, using docs I downloaded, but debian still gives me some trouble since an installed service automatically loads and runs, and for example I can't figure out how to make a service listen internally only (but that's another subject, and partially solved only recently).
Just some guidance/advice on a few of the questions at the top would be really appreciated. Not a total newbie, ran apache on suse for about 3 years without a problem.
Apparently those visions included lots of shifting colors...
People will pass up steak once a week, for crap every day.
I'll have to chime in and join the speculation that the problem lies with CF. I didn't even know CF would run under Apache.
Try installing phpBB, it's free, and moderately pretty by default. The only hitch would be migrating your existing user accounts. If you have their passwords in plaintext, just examine phpBB's registration code, and write a script to insert your existing users into phpBB's database.
I have phpBB running on a site with about 8,000 users that gets 1500+ posts a day. Works great and it's free!
Naked Apache 1 and 1/3...
Nothing sneaky was done - the CEO still knows it's open source - but now he has a phone number to call and can drag someone to his office.
Rather than laugh, I'd say go for it. If your friend owns a suit and prints a nice business card it could be win/win for everyone.
It is worth noting that the Content-Length security problem is in mod_proxy, not in the main daemon.
See CAN-2004-0492 for details.
Kernel developers today released the eagerly awaited linux kernel 1.2.14. Everyone should update to this latest version as soon as possible to make use of the security fixes that this update provides.
perl -e 'print $i=pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10);'
There was a security flaw with an integer variable field? Hrm. I feel really safe knowing they are making mistakes programming global variables, heh.
I really hope that, with this post, this is a hint of things to come at /.
/. special in the past make it to the front page again. Instead we're getting game reviews, movie reviews and politics. Sounds more like a mainstream news source now, doesn't it?
/. gave off before because, at the end of the day, that's all it is. A tagline.
I really think that overall feel of slashdot has changed and not necessarily for the better. I'd really like to see kernel releases, Gnome & KDE flamewars, Quickies, obscure language write-ups and everything else that made
The buzz of the open source world fell flat the last couple of years. I really hope it wasn't because of the market crash and that the core of the excitement wasn't the dream of cashing out by installing linux everywhere.
Open source, I think most people still don't realize, is the source of true power in speech in this day and age. If it wasn't for projects like Linux, Apache, MySQL, PHP/Perl/Python, etc. the web would be dominated by large corporations who would be the only ones capable of paying the large sums of cash for web-service software that would have no doubt been that most expensive software out if not for the free-as-in-beer-speech competition. Open source bestowed the average man a voice in the newest of media channels.
I truely hope the energy & excitement due to that fact never leaves... especially here on Slashdot. The editors shouldn't let the tagline "News for Nerds. Stuff that matters." limit the vibe
I can't wait for release 1.3.37
qmail has bugs, just no bugs that affect security. But they are bugs nonetheless.
.qmail file. I can't remember the exact details of that.
One bug is to do with insufficient checking of a counter, so it wraps at 2GB. The worst case here is that the program crashes, I believe. I don't think it is exploitable.
Another bug is a crash on parsing a slightly weird
Then there are various other things that you could consider bugs. qmail doesn't comply with the current Internet standards. If you restrict bugs to mean "doesn't function as originally designed", then these are not bugs. But I think they would be considered bugs by most people, since they affect qmail's interaction with other mail software.
Hmm, I can't seem to find the updated windows version.
Change is certain; progress is not obligatory.
when do we get to see version 1.3.37? hhohohoeohoeoohe
I'm not trying to troll, but many people make this mistake. Next time you think about migrating to a product, visit the products website to research what the latest production release is and look at a product roadmap to see if it would be worth wile to wait until a newer version becomes availiable. Then after you have done all of the research, you can present your findings to your higher ups in a manner that allows them to make an informed choice. That works wonders.
Well.. maybe. Or Maybe not. But Definitely not sort of.
sidestepping points like "genocide" with:
Trains, planes, cars, rockets, telescopes, tires, telephones, radios, television, electricity, atomic energy, computers, and fax machines. All miracles made possible by the minds and spirits of men with names like Ampere, Bell, Caselli, Edison, Ohm, Faraday, Einstein, Cohen, Teller, Shockley, Hertz, Marconi, Morse, Popov. Ford, Volta, Michelin, Dunlop, Watt, Diesel, Galileo, and other "dead white males."
is laughable.
You killed how many thousand people?? what have you to say for yourself?
We invented fax machines!
but I guess that was my question, what makes you proud to be white.
One other good example is the Space Shuttle's Accent software. And some other software (key word "some") used in the aerospace industry. In the case of the shuttle they spent LOTs of time revieing it so much so that productivity was on the order of only a very few lines of code per programmer per month. something like three or four lines. They also had to write thier own compiler and system software and verify that line by line as well. On top of that review-heavy method they contracted to two companies to write the code independently twice and they were not allowed to communicate. Both codes are run at the same time and the output is compared bit by bit. Writing perfect code means hireing a few comittees of experts to sppend years in review, debate and discuss every space and comma on a work the size of a novel. It's darn expensive. I work in that industry but I'm sure glad I get to develope and not do verification work, I'd go nuts.
Just as an example. I'd get a little form that had been signed off by a review committee that describbed some small change in the way some part inside a missle would work. I'd have to design a change and show it to my boss. But the boss woud only look at it after I'd had it reviewd by one other engineer. Boss OKs design. I write code, show it to one other engineer then to boss. Then I get to present it in a conference room on a projector to a room full of people who will grill you over every line. Almost always I'd have to change something then repeate the process. Along with the code I'd also have to prevent a "test plan" in the conference room and the pllan would need approval too.. Much of my time was taken up either presenting my stuff or sitting in the room watchinge other engineer present thier stuff. I would do the first levle of test on my stuff but we had a test group that would do more formal verification.
If you are a nigger, you chop clitoris and sold your own brothers into slavery. If you are a nigger, you gang bang in the hood. If you are a chink, you cultural revolutionized and murdered thousands under MAo in the 60's. If you are a Jap you murdered uncountable people in Nanjing. If you are a Gook, Kim Jong Il and Kim Sun Il murdered millions and starved many more, if you are Islamic, your religion murdered more than any weapons or anything in human history.
We the white people have been battling heathens like you forever. We here in America have taken the best, even if they are nigger kind, and made them make us better. Now you animals are coming here and invading us.
You are pathetic. You use the internet the WHITE MAN invented to piss on me the WHITE AMERICAN, I am an angel on earth compared to you. YOU ARE dirty, brown disgusting. You are worthless and your kind pollutes the gene pool and makes us less likely to live as a species.
You will be punished by the WHITE MAN when we get sick of you. We will not let you use anything we invent will be our punsishment. Then you rot in nigger hell.
Your talking as though the internet is a thing.
Your just as much an anonymous coward as the rest of us.
Get off your horse and stop blowing hot air.
Stupid hairless monkey!
http://www.cgisecurity.com/webservers/apache
Believe me, if I started murdering people, there would be none of you left.
Or when will we get up to Apache 1.3.37?
Your answer is very much appreciated, exactly the type of answer I was looking for.
Thanks again.
As a rule, any program of reasonable complexity has bugs.
A possible exception exists for programs written by Knuth.
What is freakish is that Knuth is the only person with the ability and determination and discipline required to write a program without bugs.
Me I'd find some other term than "freakish", like phenominal, but the critical distinction is the same.
Yes, you have just been Donkey Punched by the legendary Dirty Sanchez. Revel in the luxury of knowing that the company you keep is small, and often dead.
does anybody know off hand how long they will contunue to support apache 1.x
Get your torrents...
omg I got first post!
Hello world
Such anger! Get a life dude