Apache Killer is an uncontrolled resource-consumption vulnerability in the Apache HTTP Server byterange filter. A remote client can submit an HTTP Range request containing many overlapping byte ranges. Affected servers inefficiently process and aggregate the ranges, potentially allocating excessive memory and consuming substantial CPU resources. The issue affects Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small standalone proof-of-concept/operational denial-of-service exploit for CVE-2011-3192, the Apache HTTP Server Range header vulnerability. It contains only two files: a minimal README identifying the CVE and affected Apache versions, and a single C source file, rapache2.c, which implements the exploit logic. The exploit is not part of a larger framework. The C program accepts a hostname and port as arguments, then continuously spawns threads that each resolve the target with getaddrinfo(), open TCP sockets, connect to the target, and send a crafted HTTP HEAD request. The request targets the root path and includes a very large Range header built from hundreds of overlapping byte ranges (generated in _libc_csu_fini). This is the core exploit capability: repeated delivery of malicious Range requests intended to consume server resources and cause denial of service. Operationally, each worker thread sends the payload multiple times with short sleeps, while the main loop continuously creates up to 50 threads in an endless cycle, making the attack noisy and resource-intensive. The code includes an anti-debugging ptrace check in a constructor function, but this is incidental and not part of the exploit against Apache. There are no hardcoded victim IPs or external command-and-control endpoints. The only network target is the user-supplied hostname and port. Fingerprintable protocol artifacts are the HTTP request line 'HEAD / HTTP/1.1', the hardcoded 'Host:localhost' header, and the malicious multi-range 'Range:bytes=0-' sequence extended with ',5-<n>' values up to 1299, plus keep-alive related headers. Overall, the repository's purpose is straightforward: compile and run a multithreaded C tool to remotely trigger Apache DoS conditions on vulnerable servers.
This repository contains a single Metasploit auxiliary module: 'modules/auxiliary/dos/http/apache_range_dos.rb'. The module exploits the 'Apache Killer' vulnerability (CVE-2011-3192) in Apache HTTP Server versions 2.0.x through 2.0.64 and 2.2.x through 2.2.19. It works by sending multiple HTTP HEAD requests with specially crafted 'Range' and 'Request-Range' headers containing overlapping byte ranges, which causes excessive memory and CPU consumption on the target server, potentially leading to a denial of service (DoS). The module provides two actions: 'DOS' to trigger the attack and 'CHECK' to test for vulnerability. The main configurable options are the target URI (default '/') and the number of requests to send. The exploit is operational and is implemented in Ruby as part of the Metasploit framework. No hardcoded IPs or domains are present; the target is specified at runtime.
This repository contains a Python proof-of-concept exploit (killapache.py) for CVE-2011-3192, a Denial of Service vulnerability affecting multiple versions of the Apache HTTP Server. The exploit works by sending HTTP requests with a specially crafted Range header containing a large number of overlapping byte ranges, which can exhaust server resources and cause the server to become unresponsive. The script allows the user to specify the target URL, HTTP method, user agent, and an optional proxy. It automatically spawns as many threads as the system allows to maximize the impact of the attack. The README provides background on the vulnerability and usage notes. The code is self-contained and does not rely on any external frameworks. The main entry point is killapache.py, which is written in Python 2 and is intended for use as a denial-of-service tool against vulnerable Apache servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Apache httpdのRangeヘッダ処理に起因するDoS脆弱性。記事ではApache Killerとして言及され、非破壊寄りのPoCで影響有無とバージョン推定に利用できると説明されている。Apache httpd 2.2.20以降で修正されたとされる。
A denial-of-service vulnerability in Apache HTTP Server core caused by inefficient handling of byte-range requests leading to excessive memory use.
A remotely exploitable denial-of-service vulnerability in Apache HTTP Server's byterange filter. Crafted HTTP Range headers containing multiple overlapping ranges can cause excessive memory and CPU consumption.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.