Re: [tlug] Apache config help

> While on the subject of Apache, I am probably stating the obvious, but does
> everyone know that versions up to 1.3.24 have a DoSable bug, which someone
> has now reased an exploit for?

All distributions that I use released new versions so the answer is
yes. From the apache site 
"Versions of the Apache web server up to and including 1.3.24 and 2.0 up to
and including 2.0.36 contain a bug in the routines which deal with invalid
requests which are encoded using chunked encoding."

After updating:

Debian Unstable: apache 1.3.26
Debian Stable:   apache 1.3.9_14.1 - fixed version from 
Gentoo 1.2:      apache 1.3.26
OpenBSD 3.0:     apache 1.3.19
FreeBSD 4.6:     apache 1.3.26

