Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 25th, 2011, 14:22 GMT · By Eduard Kovacs

BLOG

Apache Reverse Proxy Issue Not Patched Properly

SHARE:

Adjust text size:

Apache is expected to release another patch for the reverse proxy issue Enlarge picture - Apache is expected to release another patch for the reverse proxy issue
Prutha Parikh, a security specialist, reported that the patch released by Apache in October could still allow for an attacker to remotely access internal servers that rely on this technology.

Apache already acknowledged the problem and assigned it a new CVE to make sure it will be dealt with in the next release.

Parikh also released a proof of concept that shows how a fully patched Apache Web Server that has the RewriteRule/ProxyPassMatch rules incorrectly configured is still susceptible to an attack.

Until the issue is solved by Apache, the researcher proposes a very simple method that could act as a workaround for preventing any unfortunate incidents.

“Apache has not yet released a patch for this issue. Until a patch is released, configuring the reverse proxy rules correctly will prevent this issue from occurring,” she said.
FILED UNDER:
Apache
patch
vulnerability

TELL US WHAT YOU THINK:

708 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Apple Patches Tons of Vulnerabilities with iOS 5 and OS X 10.7.2

Rails 3.1.2 Fixes XSS Vulnerability

Bootkit Researcher P. Kleissner: Microsoft's Secure Boot a Major Improvement, Likely Still Not Bulletproof (Exclusive Interview)

Apple Fixes Man-in-the-Middle Issue in iTunes 10.5.1

Adobe Rolls Out Security Updates with Flash Player 11.1

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM