Stefen,

Yes, you're absolutely right! We can only check in that way if a server
supports byte Range headers.

killapache.pl causes that even my upgraded server is DoS'ed, but it's
rather related to my Apache's config. Probably I need to decrease a
value of MaxClients and MaxKeepAliveRequests, because I have too less
resources to handle the request of 50 forks of killapache.pl.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/839569

Title:
  Apache2 is still Range header DoS vulnerable if gzip compression is
  enabled

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/839569/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to