Skip to content
This repository has been archived by the owner on Apr 27, 2021. It is now read-only.

Update Apache / SSH Config #102

Open
luciusbono opened this issue Mar 12, 2019 · 3 comments
Open

Update Apache / SSH Config #102

luciusbono opened this issue Mar 12, 2019 · 3 comments
Assignees

Comments

@luciusbono
Copy link

Mozilla infosec noticed that the MDN Code Samples service is running a vulnerable version of Apache (2.4.6) and an SSH config that's a little outside of what our suggested configuration is.
https://www.shodan.io/host/52.0.70.144

From talking with @a2sheppy, it sounds like the instance automatically updates when it's rebooted, so it's likely that a reboot will bring Apache up to date. For the SSH config, we recommend the "Modern" configuration file specified in our suggested configuration guide.

If you need any help or assistance getting this instance cleaned up, don't hesitate to let me know and I'll make sure you get whatever resources you need!

https://github.com/mdn/samples-server
AWS Account: cloudservices-aws-dev
InstanceID: i-42a595fc

@chrisdavidmills
Copy link
Contributor

@luciusbono which service exactly are you talking about?

@luciusbono
Copy link
Author

@chrisdavidmills wow, I actually managed to not state at any point what service I was talking about. Apologies, that was sloppy on my part. This ticket came after a looooonnnng string of asking people over and over again about the same service and I guess it broke my brain - I've updated the original ticket to include the service name, sorry for the confusion!

@chrisdavidmills
Copy link
Contributor

chrisdavidmills commented Mar 13, 2019

@luciusbono no worries, thanks for the update! I've now triaged this successfully; we'll try to get round to it before too long.

@Elchi3 Elchi3 transferred this issue from mdn/sprints May 28, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants