I run a small web server. Apache Struts CVE-2017-5638 (blog.trendmicro.com) 1 points by rossrubacon 9y ago ↗ HN
[–] rossrubacon 9y ago ↗ I checked my debian install dpkg -l |grep strutsI do not have it installed. so nothing to patch. i was thinking of making a fail2ban filter to add people who scan for the exploit to a list I share among my different servers to block it but still not clear what to look for in the logs [–] rbirnie 9y ago ↗ dpkg might not show it. Struts can be bundled in any java application and you'd never know.
[–] rbirnie 9y ago ↗ dpkg might not show it. Struts can be bundled in any java application and you'd never know.
2 comments
[ 2.6 ms ] story [ 9.2 ms ] threadI do not have it installed. so nothing to patch. i was thinking of making a fail2ban filter to add people who scan for the exploit to a list I share among my different servers to block it but still not clear what to look for in the logs