Re: [Full-disclosure] Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192)

2011-08-26 Thread bodik
Dne 08/26/11 13:26, bodik napsal(a): > >>> Option 2: (Pre 2.2 and 1.3) >>> >>> # Reject request when more than 5 ranges in the Range: header. # >>> CVE-2011-3192 # RewriteEngine on RewriteCond %{HTTP:range} >>> !(bytes=[^,]+(,[^,]+){0,4}$|^$)

Re: [Full-disclosure] Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192)

2011-08-26 Thread bodik
bidden" response :( I'll digg in deeper (also to rewrite debug log) in the night because I can't reproduce it on other places ;( bodik ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Israelis, take note

2009-10-23 Thread bodik
Gadi Evron wrote: > Hi all, this message is for the Israeli community. :o) > > בואו לשתות בירה עם מנכ"ל SANS. תשלחו לי אימייל אם אתם רוצים לבוא גם > > גדי. aren't you forbidden to drik a beer ? b ___ Full-Disclosure - We believe in it. Charter: http: