Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 6A085200D08 for ; Thu, 7 Sep 2017 01:18:04 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 6879416128F; Wed, 6 Sep 2017 23:18:04 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id AD6BF1609E3 for ; Thu, 7 Sep 2017 01:18:03 +0200 (CEST) Received: (qmail 400 invoked by uid 500); 6 Sep 2017 23:18:01 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 386 invoked by uid 99); 6 Sep 2017 23:18:01 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 06 Sep 2017 23:18:01 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id 99FCA18B61E for ; Wed, 6 Sep 2017 23:18:00 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 2.379 X-Spam-Level: ** X-Spam-Status: No, score=2.379 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=2, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=disabled Authentication-Results: spamd3-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id rhc7DuEgzfU9 for ; Wed, 6 Sep 2017 23:17:56 +0000 (UTC) Received: from mail-vk0-f51.google.com (mail-vk0-f51.google.com [209.85.213.51]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTPS id B0EA35FC69 for ; Wed, 6 Sep 2017 23:17:55 +0000 (UTC) Received: by mail-vk0-f51.google.com with SMTP id m142so6673431vkf.2 for ; Wed, 06 Sep 2017 16:17:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=csaqayV7OqLPDGL1xUglDeQu4cPk9zrVs81VhFAHUqo=; b=ug49cmIX5QBqa9/19G3yrXjbtYLc1TnuqqmgfgkSCFoKEROLtlietL95u5ChNBmiAM jnvWkZzsRPCepF0ByV0QIEFJw444yi777yvhxmSURnAHntXCB3vkB97bPUUAvsxoAG6D uAQFvGdIAngUrQx2yMma+fG5tqKgFF6Br2OmlVivse8Rf1RHsrwm8vURPhR7o+bPbx8m WidDfDgjEZXnTRSJXSXYShHwJm0QF5Wqd9DbIVzyaROspYR5oLxJqaJu4V5bMPk8Kmio cYAyumi7ZGte2SsB06LNqFfHZhYwce3owpOQW3Brrq/OMGi0w6l0VIlM29xMo1+XCzHF kqVg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=csaqayV7OqLPDGL1xUglDeQu4cPk9zrVs81VhFAHUqo=; b=Z1FQWHqhERiaYqkWqnJiqsqCoDjqZaQ0g0Mg/e/dsICVYm5Vv0WwIUNWIGs202NPqj spbV9SfF8BqOsWneJ4jTFm+SHSPZeuisN2m68AH2aGiyV3I2LEo6wO8sK8HHgxcSYdv4 5y/6Gze2ZjuHuMOB6xNV9N2MG6NK9DBIWlHVmAcg9GZrL2OkYG2ywAtN8uuSvxhh28TV pNYmRpdwFFLBY/tov6GcD+CxYX9+k/LEcDa3Nf/MchRQnKp4S2oLJeW+5ySwIwfwb6Se 7lUyu7jQ427VKDuvecORkmv557M1naJQVa5+MI9rhomfAM6WTTovxl1DugbJpEXUO3wX rlEA== X-Gm-Message-State: AHPjjUjRQsGvfrjXzAuqHNA4v7D9YDaOqAO+ywJIK14KgvYaURRRL4D0 PLU9dA9z5u5HLMfc9xH94JP//6zkFsMw X-Google-Smtp-Source: ADKCNb4TPwCQgTfVVEDnjlrY21IBve1RN4ciXiFCeLpBdUlcObp5K9K+axIU7gLhEr+Z/db6m9DoDG1g0W2vPlW22Oo= X-Received: by 10.31.252.69 with SMTP id a66mr450614vki.33.1504739875176; Wed, 06 Sep 2017 16:17:55 -0700 (PDT) MIME-Version: 1.0 Received: by 10.176.83.193 with HTTP; Wed, 6 Sep 2017 16:17:54 -0700 (PDT) From: Sean Son Date: Wed, 6 Sep 2017 19:17:54 -0400 Message-ID: To: users@httpd.apache.org Content-Type: multipart/alternative; boundary="94eb2c14be7abd469d05588d8db9" Subject: [users@httpd] Struts vulnerability archived-at: Wed, 06 Sep 2017 23:18:04 -0000 --94eb2c14be7abd469d05588d8db9 Content-Type: text/plain; charset="UTF-8" Hello all I am new to the mailing list as well as new to Apache Struts. We all heard in the news about the vulnerability affecting Apache Struts. I have been tasked to determine which of our servers have Struts running on them. I have a few questions on how to determine if a server is running Struts or not: 1) How does one determine if a Windows server, running IIS, has the Apache Struts framework installed on it? 2) Does Apache Struts only run on Apache Webserver and Tomcat? 3) Is there a simple way to determine if a server has Struts installed, instead of logging into each of the servers and checking the programs list? I appreciate ALL help! --94eb2c14be7abd469d05588d8db9 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hello all

I am new = to the mailing list as well as new to Apache Struts.=C2=A0 We all heard in the news about= =20 the vulnerability affecting Apache Struts. I have been tasked to=20 determine which of our servers have Struts running on them.=C2=A0 I have a= =20 few questions on how to determine if a server is running Struts or not:
=
1) How does one determine if a Windows server, running IIS, has t= he Apache Struts framework installed on it?

2) Does Apache Str= uts only run on Apache Webserver and Tomcat?

3) Is there a simple way to determine if a server has Struts installed,=20 instead of logging into each of the servers and checking the programs=20 list?


I appreciate ALL help!
--94eb2c14be7abd469d05588d8db9--