Help please vunrebilities..

For beginners, flames not allowed...(just by the staff :P)
Post Reply
User avatar
hacker_00
Newbie
Newbie
Posts: 4
Joined: 07 Apr 2007, 16:00
17

Help please vunrebilities..

Post by hacker_00 »

Ok first off im not using these vunrebilitys to do any damage testing my m8's website with this vunrebility detedtor N-stealth HTTP Secrurity Scanner and it's pretty useful but it's round some high risk possible vunrebilities and it's saying things like
Old Apache Version might be susceptible to security flaws

i mean wtf does that mean (there are others but see if anyone can help with this at first)

-hacker-

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

It means that your friend is not using the newest version and there are probably a lot of exploits made for it.
"The best place to hide a tree, is in a forest"

User avatar
hacker_00
Newbie
Newbie
Posts: 4
Joined: 07 Apr 2007, 16:00
17

Post by hacker_00 »

so is there a way to use the exploits to do any damage to the website?
p.s there are these exploits too

Old PHP Versions might be susceptible to security flaws
Old mod_ssl versions might be susceptible to security flaws
Old OpenSSL version might be susceptible to security flaws

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Well that depends on what the vulnerability is and what version it is. Yes it can do damage.
"The best place to hide a tree, is in a forest"

User avatar
hacker_00
Newbie
Newbie
Posts: 4
Joined: 07 Apr 2007, 16:00
17

Post by hacker_00 »

well how would i find exploits for those vunerabilities

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Well...for example let's say your friend has version 1.3.27 of apache and you want some exploits for it. Google it, example: "Apache 1.3.27 exploits"
"The best place to hide a tree, is in a forest"

User avatar
hacker_00
Newbie
Newbie
Posts: 4
Joined: 07 Apr 2007, 16:00
17

Post by hacker_00 »

ahh thx im gonna have to report that the website isn't safe (but one thing all the passwords will be safe right?? i mean we are screwed if all the accs get deleted...)

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Depends, if the password storage is vulnerable then there is a possibility that it might get lost if you get targeted.
"The best place to hide a tree, is in a forest"

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

well, if you run a website it's a must to do regular backups anyway because nothing is 100% safe....just imagine there is a HDD crash (which happens more often than one might think). and if the version is shown as "outdated" it doesn't mean it's vulnerable at the same time...it only means it's not the up to date version, "outdated" versions can still be fully patched and secure.
but well, I have to admit apache 1.3.27 is a little strange...the up to date version of 1.3 is 1.3.37, and even distros which are known to keep older versions longer than others by patching them are already using 1.3.33... :-k

Post Reply