Vulnerabilities in Nginx allows DoS attack; Patch now

Out-of-bounds read causing DoS Attack – CVE-ID: CVE-2022-41741, CVE-2022-41742 A remote attacker might exploit this nginx vulnerability to access potentially sensitive data or launch a denial-of-service attack. The ngx_http_mp4_module module’s boundary condition while processing MP4 files is the cause of the vulnerability. A remote attacker has the ability to launch a denial of service attack, send the […]

NGINX Web Server Project Addressed a zero-day Flaw in LDAP Implementation

A zero-day vulnerability in NGINX’s LDAP Reference Implementation has been fixed by the maintainers of the NGINX web server project. The security update was released in response to this vulnerability. The app users who are proxied by the NGINX web server, the NGINX LDAP reference implementation utilizes the Lightweight Directory Access Protocol (LDAP) to authenticate. […]

New Payment Data Stealing Malware Hides in Nginx Process on Linux Servers

E-commerce platforms in the U.S., Germany, and France have come under attack from a new form of malware that targets Nginx servers in an attempt to masquerade its presence and slip past detection by security solutions. “This novel code injects itself into a host Nginx application and is nearly invisible,” Sansec Threat Research team said […]

Critical vulnerabilities in NGINX allows complete takeover of affected systems. Exploit publicly available; patch now

Nginx security teams published a report related to a critical vulnerability in their DNS resolution implementation. Tracked as CVE-2021-23017, successful exploitation of this vulnerability would allow threat actors to take full control of affected systems. The flaw does not yet receive a score in the Common Vulnerability Scoring System (CVSS). The risk increases because the […]

Attackers Can Hack Sites Running On Nginx Servers By This New PHP Flaw

If you use a PHP-based website on an NGINX server and you have PHP-FPM turned on for better performance, watch out for a newly discovered vulnerability that could allow unauthorized users to hack your website’s server remotely. The vulnerability discovered as CVE-2019-11043 concerns websites with certain PHP-FPM configurations, which are reported to be not unusual […]

New PHP Flaw Could Let Attackers Hack Sites Running On Nginx Servers

If you’re running any PHP based website on NGINX server and have PHP-FPM feature enabled for better performance, then beware of a newly disclosed vulnerability that could allow unauthorized attackers to hack your website server remotely. The vulnerability, tracked as CVE-2019-11043, affects websites with certain configurations of PHP-FPM that is reportedly not uncommon in the […]

F5 Networks Acquires NGINX For $670 Million

One of the most important software companies NGINX, which is also behind the very popular open-source web server of the same name, is being acquired by its rival, F5 Networks, in a deal valued at about $670 million. While NGINX is not a name that you have ever heard of, the reality is that you […]

rwasa High Performance Web Server Claiming to be Better than nginx and lighttpd

2 Ton Digital – a company which provides products, services and support for any company or individual that is interested in security, network performance, website speed and hardware efficiency – is claiming that they have made a web server called rwasa which is faster than nginx and lighttpd. rwasa is build using 2 Ton Digital’s HeavyThing […]