port 443

Aaron Howell aaron at kitten.net.au
Mon Aug 5 23:38:42 EDT 2002


Hmmm, you've about exhausted my knowledge of what could be up short of actually logging in and looking myself.
What I wuld be concerned about though if that machine is on the net is that in tat combination of apache, mod_ssl and openssl, all 3 products contain buffer overflows which can lead to root compromize of your machine.
You want at the very least apache 1.3.26, mod_ssl 2.8.10 and openssl 0.9.6e.
Anything before that and you're inviting yourself to get hacked.
(unless you're a redhat user in which case you want apache 1.3.23-14, mod_ssl 2.8.7-6 and openssl 0.9.6b-24)
Those invalid request types look like the result of you telnetting to the port rather than the browser spitting an error.
Sorry I can't help much more than that though, as i said, the next thing I'd do is look at the box myself, just maybe there's a problem with the slackware packages or something.
Regards
aaron
On Mon, Aug 05, 2002 at 10:20:44PM -0500, Gregory Nowak wrote:
> Sorry about that, forgot to check the log. Guess I'm starting to go insane slowly (grin).
> 
> Yes, I can still telnet to port 443 and get a connection. Here is error_log.
> 
> [Mon Aug  5 22:16:33 2002] [notice] Apache/1.3.20 (Unix) mod_ssl/2.8.4 OpenSSL/0.9.6a configured -- resuming normal operations
> [Mon Aug  5 22:16:51 2002] [error] [client 204.233.198.50] Invalid method in request ?j
> [Mon Aug  5 22:16:51 2002] [error] [client 204.233.198.50] Invalid method in request ?j
> 
> 
> Greg
> 
> On Tue, Aug 06, 2002 at 01:09:16PM +1000, Aaron Howell wrote:
> > What do your logs (specifically the  error log) say now?
> > Can you telnet to port 443 on the host?
> > Regards
> > Aaron
> 
> _______________________________________________
> Speakup mailing list
> Speakup at braille.uwo.ca
> http://speech.braille.uwo.ca/mailman/listinfo/speakup

-- 
     +----------------------------------------------------------+
    /             |\      _,,,---,,_                           /|
   /              /,`.-'`'    -.  ;-;;,_                      / |
  /              |,4-  ) )-,_. ,\ (  `'-'                    /  |
 /             '---''(_/--'  `-'\_)                         /   |
+----------------------------------------------------------+    |
| Aaron Howell                  Kitten Internet            |    |
| aaron at kitten.net.au           Internet consultancy,      |    |
| Phone: +61-417-625550         System administration,     |    |
| fax: +61-7-36010099           system design/integration. |    |
| icq: 6715521                  http://www.kitten.net.au   |    |
|                                                          |    |
|                                                          |    +
|                                                          |   /
|                                                          |  /
|                                                          | /
|                                                          |/
+----------------------------------------------------------+







More information about the Speakup mailing list