5 ms·
Ask HN: Apache 2.2.22 is outdated but not according to the webhost
After much debate with my web host Apache 2.2.22 outdated from a security scan but not according to the webhost.
Is it really not outdated as the web host says?
- mortenlarsen 12y agoYou can't really tell by the version number. For example Debian stable has Apache 2.2.22 but with security patches back-ported from Apache 2.2.29. It is quite common to stay a a certain well-tested version for a while and only fix security issues.
- ForFreedom 12y agoWhat if malware was uploaded to the websites because of the outdated apache?
- SwellJoe 12y agoWas it? If they are running the latest version from the distro vendor, and the distro vendor has maintained the software, the version should be fine. Most major Linux distributions distribute the same version of a package throughout a life cycle (i.e. CentOS 6 will have the same version of Apache for its entire 5+ years of maintained life), with backported security fixes and occasional bugfixes. That is not a bug, it's a feature. I'm not saying the Apache isn't exploitable, but you need to know more than the Apache version. You'd need to know the distro package version information, and compare it to the latest package available from the distro installed on the server.
- mortenlarsen 12y agoWell you can't really know, if it is outdated or if it has back-ported patches. But chances are that your webhost is telling you the truth, and that it is not outdated from a security perspective. They are probably running Debian.
- ForFreedom 12y agoThey are running debian, so it means there is no security breach?
- mortenlarsen 12y agoYes. At least not anything that would be fixed by running a newer version.
- deleted 12y ago[deleted]
- ForFreedom 12y agoGoing to ask them to update their apache but they say its a stable version.
- digital-rubber 12y agoOutdated and vulnerable are two different things. Still have boxes with apache 1.3 running, but all potential vulnerabilities are patched and or bad feature(s) removed. Bottomline i think is, you are unhappy with your web host. Find another that does match your particular preference.
- ForFreedom 12y agoThey pointed out that there are malware files and suggested an online security scanner. I tried it out and pointed back to them that their web server is outdated. Well my question to them was how can that be that I have malware and its okay for them to have outdated web server software. I asked them for patch dates :: didnt get a reply They said if they upgrade then all users will have problems with their websites. I have been hosting with them for over 5 years now and they are good. I may be wrong in my opinion or have over looked something so wanted to know what others think.
- stevekemp 12y agoSounds like you're unhappy with your hosting company and your preferred solution would be to choose an alternative. If you believe your hosting company is lying then staying there is not a sensible decision to make. Your server/site could be compromised. There could be malware present. That may or may not be related to the version of Apache. Most web-compromises are due to weak SSH passwords, old versions of Wordpress, or other applications. I've never yet seen a compromised host which was caused by an old version of Apache, but that isn't to say that this is impossible.
- digital-rubber 12y agoI see. And yes there have been some module/syntax changes between apache versions that makes one less motivated to upgrade. Also upgrading doesn't always give you better security, you might be introducing a new issue/bug. But i could see their reasoning, why not to upgrade/change the version. The scanner most likely does a simple version compare. The scanner assumes anything under version X.Y == vulnerable. If it would be hiding or faking the vendor and version to latest IIS (or apache, or nginx or etc), possible it would simply report all is A-Okay. Unless the scanner really test the actual exploit/vulnerabilities, i assume the simple version compare happens. Though i'm quite certain the malware didn't get *there via a method that only utilises the webserver; more likely a poor coded (php, perl, etc) script allowed 3rd parties to download/write to disk of your webserver. If for example shellshock wasn't patched in time, and there was a vulnerable cgi script or similar on the website/server, it could have been that script+bash, that has been exploited. But that doesn't make the webserver vulnerable. (even though the malicious upload/ action was executed via the webserver)
- worldbesthacker 12y agoWorld Best Hackers: Our Set of professionals provide Quality Hacking Services. We have series of testimonies from our clients Worldwide. We are Proficient in Hacking every areas of ICT which include: * Hack and access DATA FROM ANY COMPANY Web Sites * FUND TRANSFER FROM ANY BANK WEBSITE * HACK AND UPGRADE UNIVERSITY GRADES * SALES OF HACKING SOFT WARES & ONLINE Tutorials * HACK INTO YOUR PARTNER's FACEBOOK ACCOUNT without their knowledge/Notification * Hack into any GOVERNMENT AGENCY WEBSITE * HIJACK A USERNAME & PASSWORD TO ACCESS ANY SITE * Hack into SECURITY AGENCY WEBSITE and ERASE CRIMINAL RECORDS * HACK AND OBTAIN CASH ADVANCES * HACK AND OBTAIN SOCIAL SECURITY NUMBER * Hack into any DATA BASE * Hack PAYPAL ACCOUNT, MASTER CARD, AMERICAN EXPRESS etc. * MANIPULATE STOCK TRADEs * HACK INTO COURT SYSTEM AND CLEAR CRIMINAL RECORD * WE ARE EXPERTS IN DATA AND FILES RECOVERY... * HACK BANK ATM CARD, PIN and PASSWORD DEVELOPMENT NOTE We Offer Expert training on hacking and Pin Generation with our e-Book and online tutorials * Is your partner cheating on you, we can teach you how to Hack into their phone, monitor their text and conversation. * Hack and use Credit Card to shop online * Monitor any phone and email address contact us at worldbesthackers2020@gmail.com
- viktorr 12y agoIf your going to run SSL, 2.2 will be very limited
- digital-rubber 12y agoI rather use TLS nowadays, until that gets cracked and we'll have nothing \o/