WebApp Security Fengshui: Apache Range Vulnerability in Macau

Post date: Sep 8, 2011 5:26:13 AM

Apache range vulnerability have been released in August, patch and fix have been published in the end of August. In the last seminar held on 3 Sept, we have found that some big brand banks in HK still suffer from it.

Now, we simply made a fast check against those organizations in Macau, we feel surprised about the results that government, banks and universities are not ready about it yet. Hopefully, they could patch it as soon as possible.

We test them with http://apache-range-exploit.com/ and assume there are false positives and negatives.