Fix For Apache DoS Bug In the Pipes
Trailrunner7 writes with the report that "The Apache Software Foundation plans to have a fix available in the next day or so [Note: that means today, now. --Ed.] for the denial-of-service problem in Apache that was publicized late last week. The bug, which in some forms has been under discussion for more than four years, involves the way that the Web server handles certain overlapping range headers. The vulnerability is a denial-of-service bug, but it is considered serious because a remote attacker can essentially take a targeted server offline with little effort and resources. The Apache Software Foundation, which maintains the popular open-source Web server, updated its advisory on the vulnerability, saying that it expects to have a full fix available for the vulnerability within the next 24 hours."
The one thing that I've found really astounding about this whole ordeal is how despicably some members of the open source community have acted towards Apache and its developers. The pure hatred they have spewed is absurd. For such a large and widely-used piece of software, Apache has a superb record of being secure and reliable. The ridicule it has received lately, especially from the open source community, is disheartening.
Somewhat surprisingly, this criticism has been coming from PHP, Ruby and JavaScript programmers. Many of these people likely don't even know C. Yet they still feel it necessary to belittle the Apache developers for making what is actually a very obscure mistake many years back. Of course, these people delivering the criticism won't admit that their own software is far buggier and insecure than Apache. The developers of PHP would never break a critical security-related function like crypt(), right?
It's a protocol bug. Any server that implements the protocol to the letter is vulnerable. And it's not just about overlapping ranges. If the server can send a ten megabyte file, an attacker can ask it for ten million of one-byte ranges. The processing overhead will bring most servers to their knees. If the server can compress the output, an attacker can ask for ten million of compressed one-byte ranges. An attempt to execute such a request will kill just about anything. The protocol should have limited the number of ranges per request to, say, 10.
the sound of millions lazy sysadmins compaining!
This is the main exploit used by the Jester for attacks on Apache servers?
From the article:
"This problem is so obvious, my grandmother could identify it."
As a 49 yo grandmother, C programmer of 20+ years, and a feminist this offends me. They wouldn't have said grandfather.
I thought we were calling them tubes.
Nice try. That quotation isn't even in the article.
It's clearly not an obvious flaw, either. That's why Apache 1.3, 2.0, and 2.2 were affected. It went years without being detected, and Apache has had many thousands of eyes look upon its code.
Next 24 hours puts this fix release on Sunday. I, myself, can't wait to let my Apache source compiles rip upon release.
All jokes aside, what baffles me is even if you're clueless when it comes to Apache webserver security, there's plenty of best practices out there, especially using mod_security with some tuned SecRule's. The mitigation steps Apache provided (using mod_rewrite) almost identically mirror the out-of-the-box SecRule's provided at gotroot.com. This isn't a soapbox plug, I just think that this attack really isn't "new" as I've compensated for it for years on any Apache webserver setup, public or private facing. Might be a good idea for 'whomever' is supporting Apache to spend some time securing it so you don't waste your Sunday evenings.
More like a dozen.
I do pity you public-school-teacher equivalent sysadmins though, I guess.
I was thinking on the order of 10,000 connections handled by the penalty box. A server under attack might randomly choose to use 400 Bad Request, use 503 Service Unavailable, or handle the connection slowly, with the frequency of error-code responses increasing as the penalty box fills up.
Slashdot's icon for a bug is a picture of a beetle? I thought this was news for NERDS.
http://en.wikipedia.org/wiki/Hemiptera
The Apache Software Foundation plans to have a fix available in the next day or so [Note: that means today, now. --Ed.
It doesn't take a genius to see that this gets stale in a couple of hours. What is today? Now? You might like when it was submitted to slashdot? Put a numeric date in your posts!
patch for nginx
http://mailman.nginx.org/pipermail/nginx/2011-August/028779.html
Good unit tests would have caught this problem.
Spammers & Phishers - To wit:
LAMP is the favored attack for phishers & spammers:
http://www.theregister.co.uk/2011/06/10/domains_lamped/
---
PERTINENT QUOTE:
"Phishers compromise LAMP-based websites for days at a time and hit the same victims over and over again, according to an Anti-Phishing Working Group survey.
Sites built on Linux, Apache, MySQL and PHP are the favoured targets of phishing attackers,"
---
* "Read 'em, & WEEP", Open SORES people...
APK
See subject-line above, & it's obvious YOU can't handle the truth!
APK
P.S.=> The ONLY reason Apache is the most used webserver IS ZERO CO$T OF PURCHASE, period (yet another truth), NOT THAT IT IS A SUPERIOR PRODUCT vs. say, IIS7!
... apk