Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mod_rootme broken in 2.4.18-2ubuntu3.2, requires config change #1

Open
jeffmcjunkin opened this issue May 18, 2017 · 2 comments
Open

Comments

@jeffmcjunkin
Copy link

https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2

Fix is to add HttpProtocolOptions Unsafe to Apache configuration, for example as follows:

echo HttpProtocolOptions Unsafe >> /etc/apache2/apache2.conf

Hint to future GitHub-stalkers: Yes, at least one Counter Hack challenge may use this backdoor :P

@sajith
Copy link
Owner

sajith commented May 24, 2017

Thanks for the report, Jeff! And apologies about being such a laggard.

I am not really the upstream maintainer of this code, but I suppose I could at least keep the README up-to-date. I will update it.

@jeffmcjunkin
Copy link
Author

Thanks, @sajith! I didn't expect the code to be "maintained" in that sense, I was just looking to document the issue somewhere.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants