#apache
15 posts · Last used 9d
Four Apache Karaf vulnerabilities, including CVE-2026-92142, let viewer and manager users reach admin or RCE. Upgrade to Karaf 4.4.12 now.
#ApacheKaraf #KarafVulnerabilities #Apache #PrivilegeEscalation #RCE #JMX #JavaSecurity #PatchNow
https://securityonline.info/apache-karaf-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
#Tech post and #autistic #infodump...
Are Mastodon #webdev folk interested in other people's development software stacks? No idea, I guess we'll see.
Here's the current set of software tools that I use to develop web apps and sites, all running on #macOS #Sequoia.
#Apache ( #Homebrew )
#MySQL (Homebrew)
#PHP (Homebrew, shivammathur version, 8.4)
#Composer
#Node and #NPM
#WordPress (used as application framework)
#jQuery
#SASS
#Taskfile (Adrian Cooney)
#Pulsar Editor
#BBEdit
#CotEditor
#SequelAce
#HTTPie
#SSH
#Filezilla
#LibreWolf
#Vivaldi
and plenty of custom #BASH and #ZSH shell scripts.
Visuals: #Inkscape #GIMP #Krita #ImageOptim
Every tool in this post is free, and almost all of it is #FOSS. I'm not an open source idealist, purist or activist but being able to read an app's source code helps me to trust it.
Questions welcome I guess, otherwise not sure why I posted...
CISA Adds Three Actively Exploited Flaws to KEV Catalog
🔗 https://cybersecurefox.com/en/cisa-adds-langflow-tomcat-n-central-kev
#cisa #kev #catalog #langflow #rce #apache #tomcat #encryption #bypass #n-able #n-central #authentication #bypass
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
Debian 13.6: Neues Punkt-Update für „Trixie“ behebt zahlreiche Sicherheitslücken
Wichtig für Anwender: Debian 13.6 ist keine neue Hauptversion, sondern lediglich eine aktualisierte Zusammenstellung bereits bestehender Pakete. Die Versionsnummer 13 bleibt bestehen, es ändert sich also nichts an der grundsätzlichen Funktionsweise oder den unterstützten Paketquellen des Systems.
https://www.all-about-security.de/debian-13-6-neues-punkt-update-fuer-trixie-behebt-zahlreiche-sicherheitsluecken/
#debian #debian13 #Apache #Curl
Boosted by @welcome@friends.deko.cloud
Hello again, Fediverse, time for my #introduction
First off, this account exists mainly to hopefully get #fedihired hopefully so set expectations accordingly.
Boosts are appreciated.
With that out of the way, I am Dennis also known as DeKayy.
I am an OSS enthusiast currently living in the area around #Frankfurt , being fluent in both English and German.
Outside of technology, my passions lie with equality, equity, independence, generally making the world a better and more fair place.
A homelab and ever increasingly independent tech-stack is also what I call my own.
On the career side, I have been a System and Network-Administrator for nearly 4½
years and counting.
And as mentioned, currently on the lookout for new opportunities, preferable completely remote.
I manage around 20 #Proxmox nodes professionally and 3 in my personal deployments, the amount of #Debian VM's and containers (including #Docker) sits somewhere in the hundreds.
With #Ansible slowly getting established in every nook and cranny to help with the whole process.
Monitoring is done on both sides with #Zabbix and serving web-requests with either #Nginx and #Apache, though I prefer the former.
I use Let's Encrypt and Cloudflare quite a lot, also having built a certificate distribution framework to deploy those internally behind metaphorical split-brain DNS lines.
Windows Server and Puppet are also not unfamiliar to me, they are currently not frequent acquaintances.
In the direction of #DevOps experience, I use Git daily, I either setup, helped with or run Jenkins buildsystems, Gitlab instances, Gitlab-runners and more.
Development-wise I created applications, tools and helpers in C#, Java, Bash, Powershell, Lua and Python, in order of proficiency.
I bring enough social skills, experience, passion and conviction to help build and run an entire independent tech stack if one wishes for it and brings enough patience, time and budget.
What I am looking for is primarily a remote position, 60% work-from-home is my minimum.
This introduction post is getting kinda long so I will leave it here for now, reach out if you are interested.
Later, DeKayy
#sysadmin
#fedihire#fedihire_de
#fedihire_eu
Just wrote an #apache #httpd rewrite rule for the first time in years. Required multiple attempts to finally redirect /doc to /docs while I would have done it with closed eyes years ago. Triggered me to take a look at @Netcraft@infosec.exchange web server survey. How things have changed from when apache was on top (for 20 years!): https://www.netcraft.com/blog/june-2026-web-server-survey #sysadmin #http
🚛 Neuer Beitrag auf ChristiansBlog.eu
Nextcloud-Server von einer USB-NVMe auf eine interne SATA-Festplatte migrieren – ohne Neuinstallation
Ein Praxis-Tutorial zur Migration eines laufenden Debian- und Nextcloud-Servers von einer USB-NVMe auf eine interne SATA-Festplatte – inklusive GRUB, rsync, fstab und typischer Fehlerfallen.
🔗 https://christiansblog.eu/post/tutorial/serverumzug/
#NextCloud #Debian #Linux #Server #Migration #NVMe #SATA #Apache #GRUB #Tutorial #HomeServer #Selfhosting
🟡 Military Incident | 7/10
🇺🇸 🇮🇷
AH-64 Apache downed near Strait of Hormuz
A U.S. Army AH-64 Apache helicopter went down near the Strait of Hormuz. Both crew members were rescued safely. The cause is under investigation.
#OSINT #NewsGroup #MilitaryIncident #StraitOfHormuz #Apache
Replying to
@endareth@disobey.net You could use something like #Cloudflare, but I've never been a big fan of proxies in front of proxies, or I found this from searching the web just now - https://binadit.com/tutorials/implement-haproxy-waf-integration-modsecurity
I do use #Apache w/ mod_security on my cPanel & WHM box.
At home I use #Traefik with a #Crowdsec plugin that seems to work well.
Yang masih pakai #httpd nya #apache silahkan dicek, kena impact-nya gak
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html
#cve #infosec
"That 'responsible disclosure' Thing"
A post with the details of CVE-2026-23918, the double free vulnerability fixed in Apache httpd 2.4.67.
#apachehttps://eissing.org/icing/posts/responsible-disclosure/
RE: https://mementomori.social/@juergen_hubert/115984654197203481
I am having a massive outage. Again. And the hosting provider doesn't allow the installation of additional tools that might help me get to the bottom of this.
Now I am contemplating that I might host my own non-public #Apache server on my own desktop PC (running Windows 11) and run the #MediaWiki #PHP code there as a private instance for testing purposes.
Whether I can replicate this problem there or not - either should be instructice.
But since I am very much a newbie at this, can anyone point be to a good guide for this kind of thing?
Quoting
Still trying to figure out my website outages.
To recap: I have two #MediaWiki wikis and one #WordPress site. And there seems to be _some_ background process which starts soon after 23:00 UTC (or 24:00 in France, where the servers are located) which puts such a strain on the website that I get a lot of "504" errors for a few hours. The exact duration is variable - sometimes it lasts for one or two hours, and sometimes it lasts way into the morning. But I cannot identify what causes it from the Apache logs - there is no clear, consistent trigger to be found there.
Last time I asked customer support, they suggested that I check my plugins and background processes. But I don't know enough about website administration to know where to look.
For what it's worth, my WordPress website uses the following plugins (all updated to the latest versions):
ActivityPub
Contact Form 7
Include Mastodon Feed
JM Twitter Cards
Leaflet Map
MC4WP: Mailchimp for WordPress
TablePress
WP DSGVO Tools (GDPR)
The site is here:
https://sunkencastles.com/
The extensions on my wiki can be found here:
https://wiki.sunkencastles.com/wiki/Special:Version
Does _anyone_ have any idea what kinds of background processes on MediaWiki or WordPress might cause this kind of outage, and how I could check it?
#FediHelp
Open quoted post You've seen all posts



