Shellshock Security Alert & Alcatel products

cheesecake

Shellshock Security Alert & Alcatel products

Post by cheesecake »

Hello all,

There is a security alert that you may have seen called Shellshock - http://www.bbc.com/news/technology-29375636

Does Alcatel have a list of prducts that are impacted by this shellshock security vulnerability?

To check you're system for this Shellshock vulnerability - https://www.digitalocean.com/community/ ... nerability

I checked on our Alcatel OmniPCX Enterprise and found it to be vulnerable to Shellshock.


Thank you,

Cheesecake
cavagnaro

Re: Shellshock Security Alert & Alcatel products

Post by cavagnaro »

It is for all Linux Based software. Which is a lot. No fix has been released by anyone yet, even those launched have workarounds too and are still exploitable.
sylvainsjc

Re: Shellshock Security Alert & Alcatel products

Post by sylvainsjc »

Image
cavagnaro

Re: Shellshock Security Alert & Alcatel products

Post by cavagnaro »

Um.....I have seen many patches but are more workarounds. Hope this one is a patch itself.
cavagnaro

Re: Shellshock Security Alert & Alcatel products

Post by cavagnaro »

And there is ICS, teamwork, omnivista, etc that also have Linux as core.
User avatar
tgn
Member
Posts: 803
Joined: 30 Dec 2009 17:59
Location: Germany

Re: Shellshock Security Alert & Alcatel products

Post by tgn »

i think as a first action we have to think about the question... how can a possible atacker take benefit of this vulnerability...
these are mainly on linux system (like described here -> https://www.digitalocean.com/community/ ... nerability)
- Apache HTTP Servers that use CGI scripts (via mod_cgi and mod_cgid) that are written in Bash or launch to Bash subshells
- Certain DHCP clients
- OpenSSH servers that use the ForceCommand capability
- Various network-exposed services that use Bash
so for oxe you can implement trusted hosts feature and/or better set it in a server-network area behind a firewall to minimize the risk. also the webserver can be deactivated on machines with newer releases.
for the other machines that use red hat linux as a base i can ask the question again and again.... why doesnt alcatel use the distributers packages for apache and tomcat... if this can be realized the red hat patches (or workarrounds like cav say :P) can be used to be "up to date in security terms"....

regards...
--- back to basics... focus your eyes to the essential things... ---
haroun
Senior Member
Posts: 1464
Joined: 29 Mar 2010 11:09

Re: Shellshock Security Alert & Alcatel products

Post by haroun »

env 'VAR=() { :;}; echo Bash is vulnerable!' 'FUNCTION=()=() { :;};
; echo Bash is vulnerable!' bash -c "echo Bash Test"
for oxe the output
Bash is vulnerable!
Bash Test
no use of the web http (4760i) for management and maintenance 'ouf'
let us see for faxserver !!
haroun
Senior Member
Posts: 1464
Joined: 29 Mar 2010 11:09

Re: Shellshock Security Alert & Alcatel products

Post by haroun »

OFS ALSO
Bash is vulnerable!
Bash is vulnerable!
Bash Test.
WONDERFULL !
User avatar
tgn
Member
Posts: 803
Joined: 30 Dec 2009 17:59
Location: Germany

Re: Shellshock Security Alert & Alcatel products

Post by tgn »

is anyone here sucessful in hacking the bash through the webserver? ;)
--- back to basics... focus your eyes to the essential things... ---
haroun
Senior Member
Posts: 1464
Joined: 29 Mar 2010 11:09

Re: Shellshock Security Alert & Alcatel products

Post by haroun »

thanks god i haven't public adresses for oxe and ofs , and we have good guys for lan security
Post Reply

Return to “Lucent Technologies”