× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Oh!... Now I understand... but maybe this CVE points to another method
different from a simple request. I've suffered the QUALYS scans and
sometimes it's not easy to fix those CVEs

Have you checked this?
https://perishablepress.com/improve-site-security-by-protecting-htaccess-files/
El jue., 23 ago. 2018 a las 10:10, Rob Berendt (<rob@xxxxxxxxx>) escribió:

Diego,

Actually I'm trying to lock the file down. But before I try I want to
verify that my test to see if the lock down works before I try to lock it
down.

I recently got dinged on a Qualys report with:
File .htaccess Accessible
THREAT:
.htaccess contains authentication information.
IMPACT:
Unauthorized users can gather authentication information from this file.
SOLUTION:
Change the Apache configuration so the .htaccess file cannot be accessed
via the Internet.
EXPLOITABILITY:
The Exploit-DB
Reference: CVE-2000-0234
Description: Cobalt RaQ 2.0/3.0 - Apache .htaccess Disclosure - The
Exploit-DB Ref : 19828
Link: http://www.exploit-db.com/exploits/19828
ASSOCIATED MALWARE:
There is no malware information for this vulnerability.
RESULTS:
GET /.htaccess HTTP/1.1
Host: 10.10.6.129:10081
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 19 Aug 2018 08:58:28 GMT
Server: Apache
Last-Modified: Wed, 02 Dec 2015 14:09:23 GMT
ETag: "185-525ead237cac0"
Accept-Ranges: bytes
Content-Length: 389


Rob Berendt
--
IBM Certified System Administrator - IBM i 6.1
Group Dekko
Dept 1600
Mail to: 2505 Dekko Drive
Garrett, IN 46738
Ship to: Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com





From: "Diego Kesselman" <diegokesselman@xxxxxxxxx>
To: "Midrange Systems Technical Discussion" <midrange-l@xxxxxxxxxxxx>
Date: 08/23/2018 11:05 AM
Subject: Re: Curl Was: Does wget in qsHell work on IBM i?
Sent by: "MIDRANGE-L" <midrange-l-bounces@xxxxxxxxxxxx>



Rob,

I'm not sure you can access .htaccess file, but what are you trying to
do? Download that page to your disk?
El jue., 23 ago. 2018 a las 9:57, Rob Berendt (<rob@xxxxxxxxx>) escribió:

Am I using the tool right, or did access somehow get shut down?

curl http://gdisys:10080/Zend5250Emulator/.htaccess
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>500 Internal Server Error</TITLE>
</HEAD><BODY>
<H1>Internal Server Error</H1>
<P>The server encountered an internal error or misconfiguration and
was
unable to complete your request.</P>
<P>Contact the server administrator at
[no address given] to inform them of the time this error occurred,
and
the actions you performed just before this error. </P>
<P>More information about this error may be available in the server
error log.</P>
</body></html>
$


Rob Berendt
--
IBM Certified System Administrator - IBM i 6.1
Group Dekko
Dept 1600
Mail to: 2505 Dekko Drive
Garrett, IN 46738
Ship to: Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com

--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.

Please contact support@xxxxxxxxxxxx for any subscription related
questions.

Help support midrange.com by shopping at amazon.com with our affiliate
link: http://amzn.to/2dEadiD



--

Saludos

Diego E. KESSELMAN
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.

Please contact support@xxxxxxxxxxxx for any subscription related
questions.

Help support midrange.com by shopping at amazon.com with our affiliate
link: http://amzn.to/2dEadiD


--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.

Please contact support@xxxxxxxxxxxx for any subscription related questions.

Help support midrange.com by shopping at amazon.com with our affiliate link: http://amzn.to/2dEadiD




As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.