This is more of just an FYI for all of you out there running Apache and Mod_ssl together on your servers. There was a security alert issued the other day because of a worm that has been spreading through systems running those pieces of software:
Affected systems include those running Apache with mod_ssl accessing SSLv2-enabled OpenSSL 0.9.6d or earlier on Intel x86 architectures. The CERT/CC has received reports of the self-propagating malicious code that exploits a vulnerability (VU#102795) in OpenSSL. The malicious code is now referred to as Apache/mod_ssl worm, linux.slapper.worm and bugtraq.c worm.
It allows the person running the worm to gain access to the machine and do pretty much anything that they want with it, unfortunately. For more information, please see this article over on ApacheToday.com.




