<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>赵健在这里！&#124; www.zhaojian.net &#187; lighttpd</title>
	<atom:link href="http://www.zhaojian.net/tag/lighttpd/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zhaojian.net</link>
	<description>赵健在这里！- 关注生活，专注互联网。www.zhaojian.net</description>
	<lastBuildDate>Tue, 08 May 2012 23:17:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>lighttpd 1.4.x 爆高危漏洞</title>
		<link>http://www.zhaojian.net/lighttpd-1-4-x-bao-gao-wei-lou-dong/</link>
		<comments>http://www.zhaojian.net/lighttpd-1-4-x-bao-gao-wei-lou-dong/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 02:15:45 +0000</pubDate>
		<dc:creator>赵健</dc:creator>
				<category><![CDATA[电脑网络]]></category>
		<category><![CDATA[2003]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[lighttpd]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[web服务器]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[服务器]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.zhaojian.net/?p=666</guid>
		<description><![CDATA[lighttpd(发音为lighty)是一套开放源代码的网页服务器,以BSD许可证放出.相较于其他的网页服务 器,lighttpd仅需少量的 内存及CPU资源即可达到同样的效能.今天lighttpd 张贴公告修复了一个已知的严重bug.可能会给 DoS/OOM 攻击以可乘之机.Li Ming （貌似是国人） reported a serious bug in lighttpd: If you send the request data very slow (e.g. sleep 0.01 after each byte), lighttpd will easily use all available memory and die (especially for parallel requests), allowing a DoS within minutes. See: lighttpd_sa_2010_01.txt (安全公告内文) Bug #2147 The bug is tracked [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.zhaojian.net/tag/lighttpd/" class="st_tag internal_tag" rel="tag" title="标签 lighttpd 下的日志">lighttpd</a>(发音为lighty)是一套开放源代码的网页<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/%e6%9c%8d%e5%8a%a1%e5%99%a8/" title="查看 服务器 中的全部文章" target="_blank">服务器</a></span>,以BSD许可证放出.相较于其他的网页服务 器,<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/lighttpd/" title="查看 lighttpd 中的全部文章" target="_blank">lighttpd</a></span>仅需少量的 内存及CPU资源即可达到同样的效能.今天<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/lighttpd/" title="查看 lighttpd 中的全部文章" target="_blank">lighttpd</a></span> 张贴公告修复了一个已知的严重bug.可能会给  <a href="http://www.zhaojian.net/tag/dos/" class="st_tag internal_tag" rel="tag" title="标签 dos 下的日志">DoS</a>/OOM 攻击以可乘之机.Li Ming （貌似是国人） reported a serious bug in lighttpd:</p>
<p>If you send the request data very slow (e.g. sleep 0.01  after each byte), lighttpd will easily use all available memory and die  (especially for parallel requests), allowing a DoS within minutes.<br />
See:</p>
<ul>
<li><a href="http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2010_01.txt">lighttpd_sa_2010_01.txt</a> (安全公告内文)</li>
<li><a href="http://redmine.lighttpd.net/issues/2147">Bug #2147</a></li>
</ul>
<p>The  bug is tracked as CVE-2010-0295.</p>
<p>As far as we know all versions  are affected.</p>
<p>该<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/%e6%bc%8f%e6%b4%9e/" title="查看 漏洞 中的全部文章" target="_blank">漏洞</a></span>影响1.4.26以下 和  r2710 之前的所有lighttpd版本.如果你正在使用的话，</p>
<p>可 以选择<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/patch/" title="查看 patch 中的全部文章" target="_blank">patch</a></span> 修复.</p>
<p>补丁下载：</p>
<p><a href="http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch" target="_blank">http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch</a> (适用于1.4.x)<br />
<a href="http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch" target="_blank">http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch</a> (适用于1.5.x)</p>

	标签：<a href="http://www.zhaojian.net/tag/2003/" title="2003" rel="tag">2003</a>, <a href="http://www.zhaojian.net/tag/dos/" title="dos" rel="tag">dos</a>, <a href="http://www.zhaojian.net/tag/lighttpd/" title="lighttpd" rel="tag">lighttpd</a>, <a href="http://www.zhaojian.net/tag/patch/" title="patch" rel="tag">patch</a>, <a href="http://www.zhaojian.net/tag/web%e6%9c%8d%e5%8a%a1%e5%99%a8/" title="web服务器" rel="tag">web服务器</a>, <a href="http://www.zhaojian.net/tag/windows/" title="windows" rel="tag">windows</a>, <a href="http://www.zhaojian.net/tag/%e6%9c%8d%e5%8a%a1%e5%99%a8/" title="服务器" rel="tag">服务器</a>, <a href="http://www.zhaojian.net/tag/%e6%bc%8f%e6%b4%9e/" title="漏洞" rel="tag">漏洞</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.zhaojian.net/lighttpd-1-4-x-bao-gao-wei-lou-dong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

