Update WebServer?

Discussion in 'AfterDawn feedback & suggestions' started by cdavfrew, Nov 11, 2008.

  1. cdavfrew

    cdavfrew Regular member

    Joined:
    May 19, 2008
    Messages:
    1,183
    Likes Received:
    0
    Trophy Points:
    46
    I see that Afterdawn is using Apache 2.2.3. Shouldn't it be updated to 2.2.10? 2.2.3 has quite a number of vulnerabilities.... especially exploited by those who break the rules and get banned...lol

    Best Regards :D
     
  2. Ketola

    Ketola Turned ninja Staff Member

    Joined:
    Jun 10, 1999
    Messages:
    1,233
    Likes Received:
    102
    Trophy Points:
    78
    Thanks for the tip! =) We live by the CentOS update schedule, and 2.2.3 is the latest version of Apache available for the time being.

    Apache versions between 2.2.3 and 2.2.10 have patched only minor vulnerabilities - all of them in modules not used by us. Or am I mistaken?
     
  3. cdavfrew

    cdavfrew Regular member

    Joined:
    May 19, 2008
    Messages:
    1,183
    Likes Received:
    0
    Trophy Points:
    46
    Thanks for your reply.

    I was actually more concerned about these updates found in 2.2.6:

    The other updates in 2.2.8 and higher don't really concern AfterDawn's active modules (at least those I know about...), unless there is a FTP server within AfterDawn as well.

    Best Regards :D
     
    Last edited: Nov 12, 2008
  4. Ketola

    Ketola Turned ninja Staff Member

    Joined:
    Jun 10, 1999
    Messages:
    1,233
    Likes Received:
    102
    Trophy Points:
    78
    Actually we don't use mod_cache (or mod_mem_cache for that matter) at AfterDawn. Local attacks aren't a concern either since no-one outside the company has access to the servers.
     
  5. cdavfrew

    cdavfrew Regular member

    Joined:
    May 19, 2008
    Messages:
    1,183
    Likes Received:
    0
    Trophy Points:
    46
    Ok then. Thanks for clarifying! :)
     

Share This Page