Re: Fwd: bugtraq.c httpd apache ssl attack

Previously Phillip Hofmeister wrote:
> I am using RedHat 7.3 with Apache 1.3.23. Someone used the 
> program "bugtraq.c" to explore an modSSL buffer overflow to get access to 
> a shell. The attack creates a file named "/tmp/.bugtraq.c" and compiles it 
> using gcc.

One wonders why you would have gcc installed on a webserver..


