Stefan 'lerothas' D. :v_gay2: (@[email protected])

Die Open Source Programme nginx und Apache httpd sind bereits gepatcht, die Closed Source Programme von u.a. MicroSlop sind noch angreifbar. Aber Open Source isr ja viel zu unsicher und eh nur Hobby Projekte. Nicht wahr? Nur ein Client nรถtig HTTP/2 Bomb legt Webserver in Sekunden lahm https://www.golem.de/news/nur-ein-client-noetig-http-2-bomb-legt-webserver-in-sekunden-lahm-2606-209396.html #nginx #apachehttpd #MicrosoftIIS #http2bomb #opensource

LGBTQIA+ and Tech

Die Open Source Programme nginx und Apache httpd sind bereits gepatcht, die Closed Source Programme von u.a. MicroSlop sind noch angreifbar.

Aber Open Source isr ja viel zu unsicher und eh nur Hobby Projekte. Nicht wahr?

Nur ein Client nรถtig HTTP/2 Bomb legt Webserver in Sekunden lahm
https://www.golem.de/news/nur-ein-client-noetig-http-2-bomb-legt-webserver-in-sekunden-lahm-2606-209396.html

#nginx #apachehttpd #MicrosoftIIS #http2bomb #opensource

Nur ein Client nรถtig: HTTP/2 Bomb legt Webserver in Sekunden lahm - Golem.de

Bei gรคngigen Webservern wie Nginx, Apache HTTPD und Microsoft IIS lรคsst sich mit wenig Aufwand innerhalb von Sekunden der Speicher fluten.

Golem.de

Codex Discovered a Hidden HTTP/2 Bomb

14 years ago, I helped break HTTP header compression, then was asked to review the fix, which became part of HTTP/2. Life has come full circle: today we're releasing an attack I missed.

๐Ÿ’ฅ https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb

#http2 #break #http2Bomb #compression #web #http #nginx #Apache #httpd #Microsoft #IIS #Envoy #Cloudflare #Pingora #Apachehttpd #MicrosoftIIS #CloudflarePingora #webserver #server

Codex Discovered a Hidden HTTP/2 Bomb

14 years ago, I helped break HTTP header compression, then was asked to review the fix, which became part of HTTP/2. Life has come full circle: today we're releasing an attack I missed.

Calif
So polite and to the point. Thank you #ApacheHTTPD , lol.

How to deploy a #Mojolicious web app to shared web hosting with Apache and CGI?

Iโ€™m having problems configuring ".htaccess" so that all pages are transparently handled by myapp.pl as a CGI script without revealing the CGI path and without breaking links in the app.

See here for details:
https://serverfault.com/questions/1190950/setup-mojolicious-app-transparently-via-cgi-with-apache-mod-rewrite

#httpd #ApacheHttpd #CGI #Perl

Setup Mojolicious app transparently via CGI with Apache mod_rewrite

I am developing a Mojolicious web application and want to deploy it to shared web hosting which offers Apache with CGI and Perl including Mojolicious. How to configure it via .htaccess? https://my...

Server Fault
Welcome! - The Apache HTTP Server Project

Welcome! - The Apache HTTP Server Project

Today's stupid #webdev trick:

I'm using #ApacheHTTPD web server with #ServerSideIncludes, and needed to set a response header.

The solution was to set a variable in the .shtml file, e.g.

<!--#set var="OVERRIDE" value="1" -->

and in the server configuration add

Header set My-Header "new-value" env=OVERRIDE

Welcome! - The Apache HTTP Server Project

There are several security vulnerabilities in #XAMPP (#Apache #ApacheHTTPd #PHP #Perl #MySQL #MariaDB #OpenSSL #phpMyAdmin #Curl #Tomcat #libexpat), I have done the official announcement, please share! (#ApacheFriends #Bitrock #Bitnami #VMware #Broadcom) https://github.com/Neustradamus/xampp
GitHub - Neustradamus/xampp: XAMPP is not secure

XAMPP is not secure. Contribute to Neustradamus/xampp development by creating an account on GitHub.

GitHub