CVE-2007-6750
published 2011-12-27CVE-2007-6750: The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by…
PriorityP342medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
71.63%
99.4th percentile
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
Affected
117 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | <= 2.2.14 | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Nmap http-slowloris-check script detects CVE-2007-6750 (Slowloris DOS) by identifying servers likely vulnerable to partial HTTP request exhaustion attacks. ↗
- →Apache HTTP Server versions before 2.2.15 lack mod_reqtimeout, which is the primary mitigation; absence of this module is a key indicator of vulnerability. ↗
- ·Red Hat Enterprise Linux 5 and 6 ship httpd with mod_reqtimeout enabled, which mitigates the vulnerability; RHEL 4 remains unmitigated. ↗
- ·Both Apache HTTP Server 1.x and 2.x branches are affected, not just a single major version. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fx24-j44g-7fh6: The Apache HTTP Server 1
ghsa_unreviewed·2022-05-01
CVE-2007-6750 [MEDIUM] GHSA-fx24-j44g-7fh6: The Apache HTTP Server 1
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
OSV
CVE-2007-6750: The Apache HTTP Server 1
osv·2011-12-27·CVSS 5.0
CVE-2007-6750 [MEDIUM] CVE-2007-6750: The Apache HTTP Server 1
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
Apple
CVE-2007-6750: macOS Server 5.3
vendor_apple·2017-03-27·CVSS 5.0
CVE-2007-6750 [MEDIUM] CVE-2007-6750: macOS Server 5.3
Apple Security Update: About the security content of macOS Server 5.3
Product: macOS Server
Version: 5.3
CVE: CVE-2007-6750
Component: CVE-2007-6750
Red Hat
httpd: Apache Slowloris denial of service
vendor_redhat·2009-06-17·CVSS 5.0
CVE-2007-6750 [MEDIUM] httpd: Apache Slowloris denial of service
httpd: Apache Slowloris denial of service
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
Statement: This issue affects the version of httpd package as shipped with Red Hat Enterprise Linux 4. This issue is mitigated by the use of mod_reqtimeout module shipped with the httpd package in Red Hat Enterprise Linux 5 and 6.
Package: httpd (Red Hat Enterprise Linux 4) - Affected
Package: httpd (Red Hat Enterprise Linux 5) - Affected
Package: httpd (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2007-6750: apache2 - The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of ...
vendor_debian·2007·CVSS 5.0
CVE-2007-6750 [MEDIUM] CVE-2007-6750: apache2 - The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of ...
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
Scope: local
bookworm: resolved (fixed in 2.2.15-3)
bullseye: resolved (fixed in 2.2.15-3)
forky: resolved (fixed in 2.2.15-3)
sid: resolved (fixed in 2.2.15-3)
trixie: resolved (fixed in 2.2.15-3)
No detection rules found.
No public exploits indexed.
Recorded Future
Top 16 Nmap Commands: Nmap Port Scan Cheat Sheet
blogs_recorded_future
Top 16 Nmap Commands: Nmap Port Scan Cheat Sheet
# Nmap Commands: Top 16 Nmap Scan Techniques Explained
Nmap is one of the most popular network mappers in the infosec world. It’s utilized by cybersecurity professionals and newbies alike to audit and discover local and remote open ports, as well as hosts and network information.
Like many OSINT tools, Nmap stands out not only for being open-source but also for being free, multi-platform, and regularly updated each year. Plus, it's one of the most comprehensive tools available for scanning hosts, networks, and ports.
It includes a large set of options to enhance your scanning and mapping tasks, and brings with it an incredible community and comprehensive documentation to help you understand this tool from the very start. Nmap can be used to:
- Create a complete computer network map
- F
Recorded Future
Top 16 Nmap Commands: Nmap Port Scan Cheat Sheet
blogs_recorded_future
Top 16 Nmap Commands: Nmap Port Scan Cheat Sheet
## Nmap Commands: Top 16 Nmap Scan Techniques Explained
Nmap is one of the most popular network mappers in the infosec world. It’s utilized by cybersecurity professionals and newbies alike to audit and discover local and remote open ports, as well as hosts and network information.
Like many OSINT tools , Nmap stands out not only for being open-source but also for being free, multi-platform, and regularly updated each year. Plus, it's one of the most comprehensive tools available for scanning hosts, networks, and ports.
It includes a large set of options to enhance your scanning and mapping tasks, and brings with it an incredible community and comprehensive documentation to help you understand this tool from the very start. Nmap can be used to:
Create a complete computer network map
Fi
HackerOne
solving TOR vulnerability, in other to make bruteforce difficult
hackerone·2023-11-28·CVSS 5.0
[MEDIUM] solving TOR vulnerability, in other to make bruteforce difficult
solving TOR vulnerability, in other to make bruteforce difficult
actually this is result on my recent vulnerability scan on the TOR website below:
135/tcp filtered msrpc no-response
139/tcp filtered netbios-ssn no-response
443/tcp open https syn-ack ttl 51
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-iis-webdav-vuln:
|_ ERROR: This web server is not supported.
| http-slowloris-check:
| VULNERABLE:
| Slowloris DOS attack
| State: LIKELY VULNERABLE
| IDs: CVE:CVE-2007-6750
| Slowloris tries to keep many connections to the target web server open and hold
| them open as long as possible. It accomplishes this by opening connections to
| the target web server and sending a partial request. By doing so, it starves
Bugzilla
CVE-2012-5568 tomcat: Slowloris denial of service
bugzilla·2012-11-26·CVSS 5.0
CVE-2012-5568 [MEDIUM] CVE-2012-5568 tomcat: Slowloris denial of service
CVE-2012-5568 tomcat: Slowloris denial of service
The Slowloris denial of service tool has been found to affect Tomcat.
Discussion:
Statement:
This issue affects tomcat and jbossweb as shipped in various Red Hat products. This issue can be mitigated using appropriate firewall configuration, as noted here:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-6750
This issue can also be partially mitigated by configuring an appropriate timeout using the connectionTimeout property for the relevant Connector(s) defined in server.xml, but testing shows that some variants of the attack may still be effective with this configuration. The tomcat project has advised that although this flaw can affect tomcat, there is no good solution available, and the tomcat security team does not consider i
Bugzilla
CVE-2007-6750 httpd: Apache Slowloris denial of service
bugzilla·2009-06-26·CVSS 5.0
CVE-2007-6750 [MEDIUM] CVE-2007-6750 httpd: Apache Slowloris denial of service
CVE-2007-6750 httpd: Apache Slowloris denial of service
Last week a tool, Slowloris, was released designed to perform a denial of service attack against various TCP servers; including Apache, Squid, and others.
The Apache Software Foundation treated this as a known issue as:
http://httpd.apache.org/docs/trunk/misc/security_tips.html#dos
See also http://marc.info/?l=apache-httpd-dev&m=124583517602035
We will continue to monitor this issue and should the Apache team decide there are changes that can help mitigate this issue within Apache itself we will evaluate those and if we can provide them as updates.
Discussion:
Here is an example of an iptables command which can be used to limit the number
of concurrent connections that can be established to port 80 from a single
client host:
#
CTF
Easy / RP:Nmap
ctf_writeups
Easy / RP:Nmap
to read [link](https://docs.google.com/document/d/1q0FziVZM3zCWhcgtPpljVPzkBX0fMAh6ebrXVM5rg08/edit)
# Nmap Quiz
1. help = -h
2. Syn Scan = -sS
3. UDP Scan = -sU
4. OS detection = -O
5. service verstion detection = -sV
6. verbosity flag = -v
7. very verbose = -vv
8. output in xml format = -oX
9. Aggressive scan = -A
10. set timing to max = -T5 (1-5)
11. specific port = -p
12. every port = -p-
13. use a script = --script
14. use script in vulnerability category = --script vuln
15. skip ping = -Pn
# Nmap Scanning
1. syn scan = ```nmap -sS```
2. scanning first 10000 port = ```2```
```console
nmap -sS 10.10.121.13
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-02 21:48 EDT
Nmap scan report for 10.10.121.13
Host is up (0.047s latency).
Not shown: 998 closed ports
PORT STATE SERVICE
22/tcp
CTF
LazyAdmin / README
ctf_writeups·CVSS 5.0
[MEDIUM] LazyAdmin / README
# LazyAdmin
Have some fun! There might be multiple ways to get user access.
- What is the user flag?
- `nmap -sV -sC `. There are two services exposed: 22/tcp (ssh) and 1583/tcp (simbaexpress)
- `nmap --script=vuln `
- Nmap scan report for 10.10.58.33
Host is up (0.081s latency).
Not shown: 998 closed ports
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-enum:
|_ /content/: Potentially interesting folder
| http-slowloris-check:
| VULNERABLE:
| Slowloris DOS attack
| State: LIKELY VULNERABLE
| IDs: CVE:CVE-2007-6750
| Slowloris tries to keep many connections to the target web server open and hold
| them open as long as possible. It accomplishes this by opening connections
http://archives.neohapsis.com/archives/bugtraq/2007-01/0229.htmlhttp://ha.ckers.org/slowloris/http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.htmlhttp://marc.info/?l=bugtraq&m=136612293908376&w=2http://www.securityfocus.com/bid/21865http://www.securitytracker.com/id/1038144https://exchange.xforce.ibmcloud.com/vulnerabilities/72345https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19481http://archives.neohapsis.com/archives/bugtraq/2007-01/0229.htmlhttp://ha.ckers.org/slowloris/http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.htmlhttp://marc.info/?l=bugtraq&m=136612293908376&w=2http://www.securityfocus.com/bid/21865http://www.securitytracker.com/id/1038144https://exchange.xforce.ibmcloud.com/vulnerabilities/72345https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19481
2011-12-27
Published