<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Acunetix</title>
	<atom:link href="http://ja.meswilson.com/blog/2007/03/28/acunetix/feed/" rel="self" type="application/rss+xml" />
	<link>http://ja.meswilson.com/blog/2007/03/28/acunetix/</link>
	<description></description>
	<lastBuildDate>Fri, 26 Feb 2010 11:47:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Eric</title>
		<link>http://ja.meswilson.com/blog/2007/03/28/acunetix/comment-page-1/#comment-1825</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Wed, 07 Nov 2007 19:35:27 +0000</pubDate>
		<guid isPermaLink="false">http://ja.meswilson.com/blog/2007/03/28/acunetix/#comment-1825</guid>
		<description>found a scanner called &quot;Maui Security Scanner&quot; (www.elanize.com), i tried both of them and it seems like maui got a bigger feature set, you should have a look at it.</description>
		<content:encoded><![CDATA[<p>found a scanner called &#034;Maui Security Scanner&#034; (www.elanize.com), i tried both of them and it seems like maui got a bigger feature set, you should have a look at it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Wilson</title>
		<link>http://ja.meswilson.com/blog/2007/03/28/acunetix/comment-page-1/#comment-12</link>
		<dc:creator>James Wilson</dc:creator>
		<pubDate>Thu, 29 Mar 2007 23:07:07 +0000</pubDate>
		<guid isPermaLink="false">http://ja.meswilson.com/blog/2007/03/28/acunetix/#comment-12</guid>
		<description>Cool. Thanks for the comments.</description>
		<content:encoded><![CDATA[<p>Cool. Thanks for the comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oswald</title>
		<link>http://ja.meswilson.com/blog/2007/03/28/acunetix/comment-page-1/#comment-11</link>
		<dc:creator>Oswald</dc:creator>
		<pubDate>Thu, 29 Mar 2007 16:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://ja.meswilson.com/blog/2007/03/28/acunetix/#comment-11</guid>
		<description>Thanks!!! Okay, in this case that&#039;s another false positive. ;)

Acunetix thinks you&#039;re using Apache 1.3 (with mod_ssl from www.modssl.org), but XAMPP uses Apache 2.x (with bundled mod_ssl from apache.org). These two mod_ssl&#039;s have the same name, but are different packages.</description>
		<content:encoded><![CDATA[<p>Thanks!!! Okay, in this case that&#039;s another false positive. <img src='http://ja.meswilson.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Acunetix thinks you&#039;re using Apache 1.3 (with mod_ssl from <a href="http://www.modssl.org" rel="nofollow">http://www.modssl.org</a>), but XAMPP uses Apache 2.x (with bundled mod_ssl from apache.org). These two mod_ssl&#039;s have the same name, but are different packages.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Wilson</title>
		<link>http://ja.meswilson.com/blog/2007/03/28/acunetix/comment-page-1/#comment-10</link>
		<dc:creator>James Wilson</dc:creator>
		<pubDate>Thu, 29 Mar 2007 15:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://ja.meswilson.com/blog/2007/03/28/acunetix/#comment-10</guid>
		<description>According to xampp-changes.txt, 1.6.0a.

Apache Mod_SSL SSL_Util_UUEncode_Binary Stack Buffer Overflow Vulnerability
&lt;blockquote&gt;Vulnerability description
This alert has been generated using only banner information. It may be a false positive.

A stack-based buffer overflow has been reported in the Apache mod_ssl module. This issue would most likely result in a denial of service if triggered, but could theoretically allow for execution of arbitrary code. The issue is not believed to be exploitable to execute arbitrary code on x86 architectures, though this may not be the case with other architectures. 

Affected mod_ssl versions (up to 2.8.17).

This vulnerability affects mod_ssl. 
The impact of this vulnerability
Denial of service and/or possible arbitrary code execution.

Attack details
Current version is mod_ssl/2.2.4 OpenSSL/0.9.8d mod_autoindex_color PHP/5.2.1 PHP/5.2.1 &lt;/blockquote&gt;

Apache Mod_SSL Log Function Format String Vulnerability
&lt;blockquote&gt;Vulnerability description
This alert has been generated using only banner information. It may be a false positive.

A format string vulnerability has been found in mod_ssl versions older than 2.8.19. Successful exploitation of this issue will most likely allow an attacker to execute arbitrary code on the affected computer.

Affected mod_ssl versions (up to 2.8.18).

This vulnerability affects mod_ssl. 
The impact of this vulnerability
Denial of service and/or possible arbitrary code execution.

Attack details
Current version is mod_ssl/2.2.4 OpenSSL/0.9.8d mod_autoindex_color PHP/5.2.1 PHP/5.2.1 &lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>According to xampp-changes.txt, 1.6.0a.</p>
<p>Apache Mod_SSL SSL_Util_UUEncode_Binary Stack Buffer Overflow Vulnerability</p>
<blockquote><p>Vulnerability description<br />
This alert has been generated using only banner information. It may be a false positive.</p>
<p>A stack-based buffer overflow has been reported in the Apache mod_ssl module. This issue would most likely result in a denial of service if triggered, but could theoretically allow for execution of arbitrary code. The issue is not believed to be exploitable to execute arbitrary code on x86 architectures, though this may not be the case with other architectures. </p>
<p>Affected mod_ssl versions (up to 2.8.17).</p>
<p>This vulnerability affects mod_ssl.<br />
The impact of this vulnerability<br />
Denial of service and/or possible arbitrary code execution.</p>
<p>Attack details<br />
Current version is mod_ssl/2.2.4 OpenSSL/0.9.8d mod_autoindex_color PHP/5.2.1 PHP/5.2.1 </p></blockquote>
<p>Apache Mod_SSL Log Function Format String Vulnerability</p>
<blockquote><p>Vulnerability description<br />
This alert has been generated using only banner information. It may be a false positive.</p>
<p>A format string vulnerability has been found in mod_ssl versions older than 2.8.19. Successful exploitation of this issue will most likely allow an attacker to execute arbitrary code on the affected computer.</p>
<p>Affected mod_ssl versions (up to 2.8.18).</p>
<p>This vulnerability affects mod_ssl.<br />
The impact of this vulnerability<br />
Denial of service and/or possible arbitrary code execution.</p>
<p>Attack details<br />
Current version is mod_ssl/2.2.4 OpenSSL/0.9.8d mod_autoindex_color PHP/5.2.1 PHP/5.2.1 </p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oswald</title>
		<link>http://ja.meswilson.com/blog/2007/03/28/acunetix/comment-page-1/#comment-9</link>
		<dc:creator>Oswald</dc:creator>
		<pubDate>Thu, 29 Mar 2007 07:19:05 +0000</pubDate>
		<guid isPermaLink="false">http://ja.meswilson.com/blog/2007/03/28/acunetix/#comment-9</guid>
		<description>Do you remember what Acunetix exactly complained about mod_ssl? And which version of XAMPP are you using?</description>
		<content:encoded><![CDATA[<p>Do you remember what Acunetix exactly complained about mod_ssl? And which version of XAMPP are you using?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
