[Bug 839569] Re: Apache2 is still Range header DoS vulnerable if gzip compression is enabled

Paweł Tęcza 839569 at bugs.launchpad.net
Thu Sep 8 08:40:48 UTC 2011


Stefen,

Yes, you're absolutely right! We can only check in that way if a server
supports byte Range headers.

killapache.pl causes that even my upgraded server is DoS'ed, but it's
rather related to my Apache's config. Probably I need to decrease a
value of MaxClients and MaxKeepAliveRequests, because I have too less
resources to handle the request of 50 forks of killapache.pl.

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to apache2 in Ubuntu.
https://bugs.launchpad.net/bugs/839569

Title:
  Apache2 is still Range header DoS vulnerable if gzip compression is
  enabled

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/839569/+subscriptions



More information about the Ubuntu-server-bugs mailing list