Everything, Everything

2024: January February March April
2023: J F M A M J J A S O N D
2022: J F M A M J J A S O N D
2021: J F M A M J J A S O N D
2020: J F M A M J J A S O N D
2019: J F M A M J J A S O N D
2018: J F M A M J J A S O N D
2017: J F M A M J J A S O N D
2016: J F M A M J J A S O N D
2015: J F M A M J J A S O N D
2014: J F M A M J J A S O N D
2013: J F M A M J J A S O N D
2012: J F M A M J J A S O N D
2011: J F M A M J J A S O N D
2010: J F M A M J J A S O N D
2009: J F M A M J J A S O N D
2008: J F M A M J J A S O N D
2007: J F M A M J J A S O N D
2006: J F M A M J J A S O N D
2005: J F M A M J J A S O N D
2004: J F M A M J J A S O N D
Bad Apple
Friday 12th March, 2010 12:59 Comments: 0
I'm surprised I haven't used that title sooner. I suspect a lot of other people have. Anyway, here's why Apple's bad:

Apple Tomcat 404

Firstly, it's bad security practice to return default error pages, especially ones that leak version information such as Tomcat 5.5.17.

Secondly, 5.5.17 is hideously old (1st December 2005). The latest version is 5.5.28 (that came out 19th June 2009). There are a number of security issues (look for CVEs in the changelog!) with older versions, although they mostly affect parts of Tomcat you can't normally access. There are also probably several performance issues with older versions.

PS This is what I was trying to reach, but SANS ISC had a broken link. Interestingly, if I follow the broken link again I must hit a differently configured load balanced server or something like that as I now see this:

Apple 404

Does that mean they have poor build standards too? I'm now getting:

Apple 504

Maybe I caught them at a bad time?
© Robert Nicholls 2002-2024
The views and opinions expressed on this site do not represent the views of my employer.
HTML5 / CSS3