Re: [WebDNA] PCI fubar

This WebDNA talk-list message is from

2012


It keeps the original formatting.
numero = 109178
interpreted = N
texte = Robert Minor wrote: > I have a server running apache1.3 and webdna 6.0a. After PCI testing I recieved a series of issues that had to be addressed. I was able to mitigate all of them save 1. > > Apache HTTP Server httpOnly Cookie Information Disclosure > > It seems apache1.3 is vulnerable to this attack and the only way to pass is to upgrade to apache2.2.2. > > So just a few questions. > > Can I run apache2.2 under tiger 10.4? I assume yes. > does the webdna module have to be upgraded? > if so what version? What issues can I expect? > Do I need to just rebuild the server under leopard 10.5--------------------------------------------------------- Hi Bob, There is an apache2x module for PowerPC, if that is what you are getting at. It runs with 6.0a. Donovan Donovan Brooke WebDNA Software Corporation http://www.webdna.us **[Square Bracket Utopia]** Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] PCI fubar (Donovan Brooke 2012)
  2. Re: [WebDNA] PCI fubar (Donovan Brooke 2012)
  3. Re: [WebDNA] PCI fubar (Donovan Brooke 2012)
  4. Re: [WebDNA] PCI fubar (Donovan Brooke 2012)
  5. Re: [WebDNA] PCI fubar (christophe.billiottet@webdna.us 2012)
  6. Re: [WebDNA] PCI fubar (Robert Minor 2012)
  7. [WebDNA] PCI fubar (Robert Minor 2012)
Robert Minor wrote: > I have a server running apache1.3 and webdna 6.0a. After PCI testing I recieved a series of issues that had to be addressed. I was able to mitigate all of them save 1. > > Apache HTTP Server httpOnly Cookie Information Disclosure > > It seems apache1.3 is vulnerable to this attack and the only way to pass is to upgrade to apache2.2.2. > > So just a few questions. > > Can I run apache2.2 under tiger 10.4? I assume yes. > does the webdna module have to be upgraded? > if so what version? What issues can I expect? > Do I need to just rebuild the server under leopard 10.5--------------------------------------------------------- Hi Bob, There is an apache2x module for PowerPC, if that is what you are getting at. It runs with 6.0a. Donovan Donovan Brooke WebDNA Software Corporation http://www.webdna.us **[Square Bracket Utopia]** Donovan Brooke

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

Upgrading old WebCat Database Files (1997) Document Contains No Data, Blank Pages with b4, b6 mac! (1999) frames & carts (1997) Need relative path explanation (1997) Large databases in WebCat (1997) Q: for those who use Cookies for sessions? (2004) Re:trouble (1997) storebuilder problems on RedHat 6.1 with webcat 3.08 (2000) What is WebDNA (1997) Not really WebCat (1997) Fun with Dates - revisited (1997) WebCat & Oracle (2001) Banners and sort of random display (1997) [WebDNA] o search engines index .db files? (2009) Orders.db problem (2003) Search and path arguments (1998) Authenticate (1997) Big Databases (1997) [OT] My own Hot Mail like e-mail services (2003) Possible Macv2.1b2 Merge Bug (1997)