[Bug 392759] Re: apache2 DoS attack using slowloris

2009-09-27 Thread Dekar
** Changed in: apache2 (Ubuntu) Assignee: (unassigned) => Dekar (dekar-wc3edit) ** Changed in: apache2 (Ubuntu) Assignee: Dekar (dekar-wc3edit) => (unassigned) ** Changed in: apache2 (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) -- apache2 D

[Bug 392759] Re: apache2 DoS attack using slowloris

2009-09-22 Thread Dekar
Can't you at least change the importance level? It is way more important then "wishlist", it is one of the worst things that could happen to a fresh ubuntu server installation! Concerning to the guidelines it should be high! -- apache2 DoS attack using slowloris https://bugs.launchpad.net/bugs/39

[Bug 392759] Re: apache2 DoS attack using slowloris

2009-09-21 Thread Dekar
** Changed in: apache2 (Debian) Status: New => Confirmed -- apache2 DoS attack using slowloris https://bugs.launchpad.net/bugs/392759 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in ubuntu. -- Ubuntu-server-bugs mailing

[Bug 392759] Re: apache2 DoS attack using slowloris

2009-09-21 Thread Dekar
** Bug watch added: Debian Bug tracker #533661 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=533661 ** Changed in: apache2 (Debian) Importance: Undecided => Unknown ** Changed in: apache2 (Debian) Status: New => Unknown ** Changed in: apache2 (Debian) Remote watch: None => Debia

[Bug 392759] Re: apache2 DoS attack using slowloris

2009-09-21 Thread Dekar
It is a serious remote denial of service! It can be used from a single modem line and take down a whole server without generating any logfiles except normal access logs. It's funny how you guys treat it as "Wishlist" for three months even though it's one of the worst remote denial of service attack

[Bug 392759] Re: apache2 DoS attack using slowloris

2009-09-20 Thread Dekar
highA real problem, exploitable for many people in a default installation. Includes serious remote denial of services, local root privilege escalations, or data loss. Thus it should be changed to HIGH and fixed ASAP! ** Also affects: apache2 (Deb