Re: Apache problems

2011-09-19 Thread Mattieu Baptiste
On Mon, Sep 19, 2011 at 6:37 AM, Rod Whitworth glis...@witworx.com wrote: What a pity that people don't do any searching b4 asking STFA for this list and (IIRC) find links to the PoC tool amongst other info. Yes, and this has nothing to do with OpenBSD (this time). The apache foundation

Re: Apache problems

2011-09-19 Thread ropers
On 19 September 2011 09:51, Mattieu Baptiste mattie...@gmail.com wrote: The apache foundation has adjusted the security advisory and Apache 1.3 isn't vulnerable. https://httpd.apache.org/security/CVE-2011-3192.txt Yes, fair enough, BUT that same advisory says *in its Apache 1.3 section*:

Re: Apache problems

2011-09-19 Thread Mattieu Baptiste
On Mon, Sep 19, 2011 at 6:57 PM, ropers rop...@gmail.com wrote: On 19 September 2011 09:51, Mattieu Baptiste mattie...@gmail.com wrote: The apache foundation has adjusted the security advisory and Apache 1.3 isn't vulnerable. https://httpd.apache.org/security/CVE-2011-3192.txt Yes, fair

Re: Apache problems

2011-09-18 Thread Tomas Bodzar
On Sun, Sep 18, 2011 at 2:40 AM, L. V. Lammert l...@omnitec.net wrote: On Sun, 18 Sep 2011, Jeremie Courreges-Anglas wrote: [error] (35)Resource temporarily unavailable: fork: Unable to fork new process Isn't running 4.3 kinda cranky? Only in the past six months - pretty much bulletproof

Re: Apache problems

2011-09-18 Thread L. V. Lammert
On Sun, 18 Sep 2011, Tomas Bodzar wrote: *Something* seems to be breaking, causing Apache to 'think' it's out of resources. Eg. for amd64 limit of ~4000 processes was resolved only before couple of months/weeks (not sure about correct time). A LOT of improvements from 4.3 times regarding

Re: Apache problems

2011-09-18 Thread Denis Fondras
Le 18/09/2011 15:54, L. V. Lammert a icrit : Something is borking Apache and causing it to use UP all resources in an 'unauthorized' manner, or *think* they have all bee used. Could this be linked to some Apache Killer ?

Re: Apache problems

2011-09-18 Thread Benny Lofgren
On 2011-09-18 15.54, L. V. Lammert wrote: TFTR, but you missed the original premise - the system has been running for many years with MORE children authorized, and no resource limits have *changed*, so I don't see how it can be a resource issue. Something is borking Apache and causing it to

Re: Apache problems

2011-09-18 Thread Amit Kulkarni
*Something* seems to be breaking, causing Apache to 'think' it's out of resources. Eg. for amd64 limit of ~4000 processes was resolved only before couple of months/weeks (not sure about correct time). A LOT of improvements from 4.3 times regarding performance and speed of system so you

Re: Apache problems

2011-09-18 Thread L. V. Lammert
On Sun, 18 Sep 2011, Denis Fondras wrote: Could this be linked to some Apache Killer ? That would make sense, is/was there any way to identify vectors of the Apache attacks? Lee

Re: Apache problems

2011-09-18 Thread L. V. Lammert
On Sun, 18 Sep 2011, Amit Kulkarni wrote: Recently there was a security issue with Apache. It was based on a perl script, search google. Maybe you are experiencing traffic and the realted problems because of that. Is there any way to find out if the version in 4.3 was susceptable to the

Re: Apache problems

2011-09-18 Thread Shane Harbour
On 9/18/2011 9:42 PM, L. V. Lammert wrote: On Sun, 18 Sep 2011, Amit Kulkarni wrote: Recently there was a security issue with Apache. It was based on a perl script, search google. Maybe you are experiencing traffic and the realted problems because of that. Is there any way to find out if

Re: Apache problems

2011-09-18 Thread Rod Whitworth
What a pity that people don't do any searching b4 asking STFA for this list and (IIRC) find links to the PoC tool amongst other info. On Mon, 19 Sep 2011 04:24:19 -0600, Shane Harbour wrote: On 9/18/2011 9:42 PM, L. V. Lammert wrote: On Sun, 18 Sep 2011, Amit Kulkarni wrote: Recently

Re: Apache problems

2011-09-18 Thread Shane Harbour
On 9/18/2011 10:37 PM, Rod Whitworth wrote: What a pity that people don't do any searching b4 asking STFA for this list and (IIRC) find links to the PoC tool amongst other info. On Mon, 19 Sep 2011 04:24:19 -0600, Shane Harbour wrote: On 9/18/2011 9:42 PM, L. V. Lammert wrote:

Re: Apache problems

2011-09-17 Thread Jeremie Courreges-Anglas
Le samedi 17 septembre 2011 C 04:15:18, L. V. Lammert a C)crit : We have an older server (4.3) that is getting cranky - two or three times a week Apache just 'stops', and the only issue I can find is in the common error log (i.e. not one of the VHs), which shows unable to fork: [error]

Re: Apache problems

2011-09-17 Thread L. V. Lammert
On Sun, 18 Sep 2011, Jeremie Courreges-Anglas wrote: [error] (35)Resource temporarily unavailable: fork: Unable to fork new process Isn't running 4.3 kinda cranky? Only in the past six months - pretty much bulletproof for many years. $SEARCH_ENGINE $your_error_message gives, for

Re: Apache problems

2011-09-17 Thread Jeremie Courreges-Anglas
[...] Unfortunatley, that isn't the issue. It has run fine with max_clients set at 150; when this started happening, I ran it down to 64. [...] Thanks for pointing this out. Do you have any other minor detail, before I decide I definitely can't help? It isn't a resource problem, however, ..