Re: [d-security] woody apache/ssl - security issue?


On Wed, Sep 25, 2002 at 02:03:43PM +0100, Jeff Armstrong wrote:
> Symptoms:
>  Apache stops dishing pages - no log or error messages
>  netstat shows Apache still listening
>  /etc/init.d/apache stop fails to kill all apache processes
>  have to killapp apache and kill -9 some individual apache processes
>  no cores, no messages in syslog, daemon.log or messages
Can't remember the kill charactersitics but the other symptoms, failing
w/o giving any clue, are also happening if the filesystem is full and
apache cannot write new logfile entries. It starts to work again as soon
as it has free space again.

The logfile entries you've shown are absolutely harmless, I use exactly
the same strings for testing if a webserver responses.

Of course, as we are all paranoid on this list, this does not mean that it
was no DOS attack :-)

