Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

The identified vulnerability, known as CVE-2023-46604, is rated as critical with a CVSS v3 score of 10.0.

https://cybersec84.wordpress.com/2023/11/02/critical-rce-vulnerability-discovered-in-apache-activemq-servers/

simontsui, to random

Rapid7 identified suspected exploitation of CVE-2023-46604 (CVSS: 10.0 critical severity, disclosed 26 October 2023 by Apache). Rapid7 also included links to a Proof of Concept exploit, external technical details, and their own vulnerability analysis. They provided Indicators of Compromise.
Link: https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/

BleepingComputer, to random

Over three thousand internet-exposed Apache ActiveMQ servers are vulnerable to a recently disclosed critical remote code execution (RCE) vulnerability.

https://www.bleepingcomputer.com/news/security/3-000-apache-activemq-servers-vulnerable-to-rce-attacks-exposed-online/

simontsui,

@BleepingComputer CVE-2023-46604 (CVSS: 10.0 critical severity, disclosed 26 October 2023 by Apache)
Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.

The Netherlands' National Cyber Security Centrum (NCSC) states that Proof of Concept has been published publicly, and that they received a report from a trusted partner that the vulnerability has been actively and specifically exploited. https://advisories.ncsc.nl/advisory?id=NCSC-2023-0561

simontsui,

@BleepingComputer Hot off the press: "Beginning Friday, October 27, Rapid7 Managed Detection and Response (MDR) identified suspected exploitation of Apache ActiveMQ CVE-2023-46604 in two different customer environments."
Link: https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/

philipdutre, to random Dutch
@philipdutre@mastodon.online avatar

Goede langlezing om het verlengde weekend mee aan te vatten. ​​Tom Lanoye: 'We worden geregeerd door het overbetaalde schepencollege van Bommerskonte' https://www.apache.be/2023/11/01/tom-lanoye-we-worden-geregeerd-door-overbetaalde-schepencollege-van-bommerskonte

opensuse, to Redis
@opensuse@fosstodon.org avatar

Major updates in @opensuse Tumbleweed this week, including , , , GVfs, , Plasma & Frameworks. to find out what packages updated or read our weekly update. https://news.opensuse.org/2023/10/27/apache-plasma-firewalld-up-in-tw/

JeroenSH, to linguistics
@JeroenSH@lingo.lol avatar

experts are turning to cutting-edge technologies to revitalize threatened languages — and rejuvenate generations of indigenous tradition — through new approaches such as children’s books and smartphone apps | Taipei Times

https://www.taipeitimes.com/Nes/feat/archives/2023/10/24/2003808130

nixCraft, to linux
@nixCraft@mastodon.social avatar

Here is how to install Perl in Fedora , including the latest version of mod_perl with Apache (HTTPD) to run dynamic web pages/handlers in Perl https://www.cyberciti.biz/faq/install-perl-in-fedora-linux-using-dnf-command/

dboehmer,

@nixCraft Please use mod_perl only if you want to control the frontend in fancy ways, e.g. in different phases of request processing. It's a Frankenstein of httpd and Perl.

For 99% of web applications, better use a dedicated application server for separation of concerns, like Plack in the ecosystem.

governa, to RedHat
@governa@fosstodon.org avatar

How to Install Kafka on -Based Distributions

https://linuxtldr.com/installing-apache-kafka/

parigotmanchot, to php French
@parigotmanchot@mastodon.social avatar

: Configure a WEB site (PHP-Apache-Mysql) in 5 minutes with Docker - Doc4Dev - Apache + PHP + MySQL en Docker très simplement.
PHPMyAdmin : https://doc4dev.com/en/install-phpmyadmin-for-mysql-under-docker-with-docker-compose/

Autre exemple identique ou presque avec des options plus poussées : https://www.bgs-associes.com/configurer-une-application-avec-apache-php-mysql/ : https://doc4dev.com/en/create-a-web-site-php-apache-mysql-in-5-minutes-with-docker/

icing, to random
@icing@chaos.social avatar

In case you have not already had enough of the "HTTP/2 Rapid Reset" attack (remember? last week?), here is my blog on the situation and history in Apache httpd: https://github.com/icing/blog/blob/main/h2-rapid-reset.md

icing, to random
@icing@chaos.social avatar

Apache httpd 2.4.58 has been released: https://httpd.apache.org

My summary of the changes I made: https://github.com/icing/blog/blob/main/httpd-2.4.58.md

Thanks to all the people who helped!

sormuras, to Java

Introducing the Oracle #Java Platform Extension for Visual Studio Code

"Our Java language server is a slimmed down version of the one we developed in the #Apache #Netbeans project, and it is based on the #OpenJDK #JDK ’s javac compiler [...] support for new JDK features as soon as they are introduced, even during Early Access of the JDK."

https://inside.java/2023/10/18/announcing-vscode-extension/

icing, to random
@icing@chaos.social avatar

From the google doc about the HTTP/2 Rapid Reset attack:

„In a typical HTTP/2 server implementation…“

If you run Apache httpd, you do not have such. Since 2016, we have measures in place that limit clients in how they can pull our chains.

This attack pattern will waste cpu on your httpd, but it will not hit your backends.

In addition, nghttp2 will make a release that limits the cpu waste.

YurkshireLad, to linux
@YurkshireLad@mastodon.social avatar

Looking for a nice web based file manager for an server. Apache lets you browse the directory tree but you can't do anything with the files. Must support an existing htpasswd file.

YurkshireLad, to iOS
@YurkshireLad@mastodon.social avatar

Weird, if I mount an resource in an or file manager, the index shows me folders I don't have the rights to access. They're hidden in the web UI.

alexelcu, to random
@alexelcu@social.alexn.org avatar

Apache is replacing in Play Framework ❤️😍

I really wish Lightbend well, I hope they thrive, but blowing up the FOSS ecosystem around Akka was a foreseeable consequence of its licensing turning proprietary. All FOSS projects will predictably move to Pekko, and Pekko isn't a drop-in replacement (due to the inevitable change in packages), which puts Akka in a very tough spot.

N.b., version 2.9 is probably the last release with support for Akka.

https://github.com/playframework/playframework/releases/tag/2.9.0-RC2

alexelcu,
@alexelcu@social.alexn.org avatar

Dust hasn't settled yet on Apache , but I really believe it will thrive.

This is the true power of . When you don't agree with the direction, you can fork from the last adequate version! Resources are required, but where there's a need, there's a way 💪

Furthermore, in the case of Pekko, was the best organization to take this on because they have adequate processes that give credibility to such forks.

fell, to PostgreSQL
@fell@ma.fellr.net avatar

God I hate so much...

  1. I have to jump hoops to manage my server, because my Plesk license doesn't cover PostgreSQL.
  2. It keeps annoying me about buying shit.
  3. It defaults to and supports only as a caching proxy in front of Apache.
  4. Said NGINX support is broken af, making you click options in a specific order for them to work at all.

I want to get rid of it so bad but I don't want to set up all those servers from scratch 😭

danluu, to random
@danluu@mastodon.social avatar

As a follow-up to https://mastodon.social/@danluu/109798007902048311, I wonder why there isn't a serious, well-funded, attempt to create a modern forum

If you look at Wikipedia's list of forum software, it's all ancient except discourse, and discourse seems unlikely to ever be something great for users

Its performance is famously terrible. People often point out how unusable it is unless you have a fast phone and the founder's response to this has been to rant about how Qualcomm sucks and need to make faster processors

devnull,
@devnull@crag.social avatar

@supermathie @nodebb @danluu I'm glad to hear that, but I'm surprised it was a commit to the Discourse repo to ban Bing (even if temporarily)? In my experience, bad actors slamming your server still end up tying up resources if they hit the app. We advise our users to head it off at the pass at the reverse proxy level (e.g. , , etc.)

vwbusguy, to random
@vwbusguy@mastodon.online avatar

Had a crazy idea to support tls-alpn for . I think I can make it work by setting up a container but map 443 to a high local port, then proxy all .acme_challenge to caddy, and have the same domains listed in caddy with the generated certs volume-mounted to the location that apache is set up to read, then using inotify to restart apache on change to those cert files.

https://caddy.community/t/using-caddy-to-keep-certificates-renewed/7525

Tipa, to javascript
@Tipa@gamepad.club avatar

front end served by , written in with 3 game engine, back end served with (soon AWS ) and written in . There's a lot going on but it sorta works. This proves my idea to offload the processing to a remote back end driving a thin client works.

It plays terribly at the moment, but it's good enough to work on the UX.

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

CVE-2023-39265 is related to a bypass issue in URI connections to the SQLite database used for the metastore. This vulnerability enables attackers to execute data manipulation commands.

https://cybersec84.wordpress.com/2023/09/08/apache-superset-servers-vulnerable-to-rce-attacks/

fell, to mastodon
@fell@ma.fellr.net avatar

: Don't forget to enable gzip compression in your or or whatever you're using as a reverse proxy for to improve performance on slow connections. I have seen requests that could be compressed to 10% their original size!

fell,
@fell@ma.fellr.net avatar

@Tealk Well, I am stuck with because of other services on the same machine, so I had it disabled all this time.

itsfoss, (edited ) to linux
@itsfoss@mastodon.social avatar

Share your Linux journey in the comments below! 🙂 🐧

hophophop, (edited )
@hophophop@mastodon.social avatar

@itsfoss In 1997 or 1998 I had to live-edit some typos in html pages. I'd say it was an webserver living inside a server, and I had to login via telnet session (ISDN). The editor I used was nano.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • GTA5RPClips
  • thenastyranch
  • ethstaker
  • everett
  • Durango
  • rosin
  • InstantRegret
  • DreamBathrooms
  • magazineikmin
  • Youngstown
  • mdbf
  • slotface
  • tacticalgear
  • anitta
  • kavyap
  • tester
  • cubers
  • cisconetworking
  • ngwrru68w68
  • khanakhh
  • normalnudes
  • provamag3
  • Leos
  • modclub
  • osvaldo12
  • megavids
  • lostlight
  • All magazines