From owner-freebsd-security@FreeBSD.ORG Fri Jul 26 11:40:40 2013 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 53F1C3FE for ; Fri, 26 Jul 2013 11:40:40 +0000 (UTC) (envelope-from feld@freebsd.org) Received: from out1-smtp.messagingengine.com (out1-smtp.messagingengine.com [66.111.4.25]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 2A87523AA for ; Fri, 26 Jul 2013 11:40:40 +0000 (UTC) Received: from compute2.internal (compute2.nyi.mail.srv.osa [10.202.2.42]) by gateway1.nyi.mail.srv.osa (Postfix) with ESMTP id 271FC2129F for ; Fri, 26 Jul 2013 07:40:35 -0400 (EDT) Received: from web3 ([10.202.2.213]) by compute2.internal (MEProxy); Fri, 26 Jul 2013 07:40:37 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=message-id:from:to:mime-version :content-transfer-encoding:content-type:subject:date; s=smtpout; bh=rPM0f0UyesldrTJpTObvG8USZvE=; b=n33omQql+8bt2avV5w1XMVq8512b VvSSahKVuWC5Alrv7qwT50SNCNYZGQzuDryUTnJE6WRsRLfgGATLvvc8yE/Uax29 sp/+fK+80ESdEWrzOneXW8GWOwyPJ2k/NXyughvm8XxM0PD3b3w9K9BVuTMvEcE1 UP2e/pO5Oo/s+5Y= Received: by web3.nyi.mail.srv.osa (Postfix, from userid 99) id 8C9D4B01D6D; Fri, 26 Jul 2013 07:40:35 -0400 (EDT) Message-Id: <1374838835.16740.1844463.72B1ED2B@webmail.messagingengine.com> X-Sasl-Enc: Qv03uXNTCSpoWVBXJZdDZB24KDO8qeJ6GmD3vLmF3nal 1374838835 From: Mark Felder To: freebsd-security@freebsd.org MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Type: text/plain X-Mailer: MessagingEngine.com Webmail Interface - ajax-23e62cd3 Subject: nginx exploit / accept filters Date: Fri, 26 Jul 2013 06:40:35 -0500 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Jul 2013 11:40:40 -0000 As described here: http://lists.grok.org.uk/pipermail/full-disclosure/2013-July/091084.html If I understand this correctly our accept filters will have zero effect on stopping this exploit, correct?