Forgot your password?

typodupeerror

Comment: Re:without the knowledge of the site visitor (Score 1) 273

"my ISP serves me their self-signed cert instead of Slashdot's real one."

You see a page/popup that says "this certificate is bogus, somebody is fooling around with your connection". From that point on, if you decide to proceed to the site, you are your own worst enemy.

Comment: Re:Not just an Apache bug (Score 2) 49

by Kickasso (#37228300) Attached to: Fix For Apache DoS Bug In the Pipes

How did you test? nginx does honor Range requests. The Apache killer will report that nginx not vulnerable, so what, it misreports PHP-based Apache installations too. However, this attack can be performed in more than one way. Maybe you should know that nginx maintainers have released a patch today. I wonder why.

I have read that IIS is vulnerable to this too, not sure if this is true, I have no IIS installations that I can check.

I'm not sure what Cherokee does so I can't comment here.

Abraham Lincoln didn't die in vain. He died in Washington, D.C.

Working...