Apache vulnerable to easy DOS attack - workaround available
mail-archives.apache.org
mail-archives.apache.org
Option 1: (Apache 2.0 and 2.2)
# Drop the Range header when more than 5 ranges.
# CVE-2011-3192
SetEnvIf Range (,.*?){5,} bad-range=1
RequestHeader unset Range env=bad-range
# optional logging.
CustomLog logs/range-CVE-2011-3192.log common env=bad-range
Option 2: (Also for Apache 1.3)
# Reject request when more than 5 ranges in the Range: header.
# CVE-2011-3192
#
RewriteEngine on
RewriteCond %{HTTP:range} !(^bytes=[^,]+(,[^,]+){0,4}$|^$)
RewriteRule .* - [F]Option 2 produced no such hike, and protected the server from attack.
"When using a third party attack tool to verify vulnerability - know that most of the versions in the wild currently check for the presence of mod_deflate; and will (mis)report that your server is not vulnerable if this module is not present. This vulnerability is not dependent on presence or absence of that module."
Not sure if that's how you are checking for vulnerability, however it was reporting that my site was "not vulnerable" when it was very much so.
The way I check for the vulnerability is based on the original perl script in the OP link. I submit 20 byte range requests and check for a Partial string in the response, if I see that I assume that the server is vulnerable. It's more of an educated guess, but I've been using it myself to fix misc servers I have running.
created Thu, 25 Aug 2011 14:32:30 UTC
Wow, that's nice and clean for a morning project (and thanks!)I've used it for a recent one-off project and it's great and meant for that kind of things: good looking pages even if they were thrown together quickly.
Range: bytes=100-200, 600-800, 1500-
If the server supports ranges, it will respond with a 206 Partial Content status, and send a multipart/byteranges response body, which looks like this http://www.freesoft.org/CIE/RFC/2068/225.htm. Basically a delimited string containing all the ranges.
This is useful for some streaming audio/video formats and especially for large pdfs. IIRC, pdfs typically have header information at the end of the file, so it's useful for a pdf reader to get the end of the file first.
Note that this means that downloads are not resumable, which can easily annoy site users even if there is no multimedia involved. You only need to specify one range in the header in this case, but to do that you need option #1.
RewriteCond %{HTTP:range} !(^bytes=[^,]+(,[^,]+){0,1}$|^$)
RewriteRule .* - [F]
(for those that don't speak regex: the 0,1 allows either one or none range headers to be accepted, more or less will fail to be served anything)That will allow downloads to still resume and it works in any version of apache.