Top ASX-listed companies vulnerable to Apache DoS exploit

Powered by SC Magazine
 

Attack launched over 3G

Twenty six of the top 200 ASX-listed companies are vulnerable to an Apache web server denial of service exploit according to a penetration testing company.

The exploit issues partial content requests to Apache httpd which causes the daemon to swap memory to the file system, eventually triggering a denial of service attack

The attack was released by researcher Kingcope on the Full Disclosure mailing list.

HackLabs director Chris Gatford tested the exploit and found it could work over a 3G mobile connection.

"We edited the exploit script and removed the DoS (Denial of Service) payload and then used it determine how many sites could be affected," Gatford said.

Gatford said 91 of the top 1000 Australian sites listed by Alexa appeared vulnerable to the exploit.

HackLabs said firewalls, intrusion prevention systems or IP table rules could be used to mitigate the attack.

Curl can be run to test exposure to the attack by determining if partial content is supported on by Apache;

curl -H "Range:bytes=1-" -I http://target.com | grep Partial

Apply a patch to add support to turn off partial content.

Copyright © SC Magazine, Australia


Top ASX-listed companies vulnerable to Apache DoS exploit
Tags
 
 
 
Top Stories
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
ATO investigates 25 tech giants in tax hunt
Prepared to take tax evaders to court.
 
Immigration, Customs restructure IT leadership
Customs CIO promoted into transformation role.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3009

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 954

Vote