Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
I run a small web server. Apache Struts CVE-2017-5638 (trendmicro.com)
1 point by rossrubacon on March 10, 2017 | hide | past | favorite | 2 comments


I checked my debian install dpkg -l |grep struts

I do not have it installed. so nothing to patch. i was thinking of making a fail2ban filter to add people who scan for the exploit to a list I share among my different servers to block it but still not clear what to look for in the logs


dpkg might not show it. Struts can be bundled in any java application and you'd never know.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: