<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unix shell shock vulnerability: Is Splunk web or mgt port vulnerable to attacks when running on Unix system with shell shock vulnerability? in Security</title>
    <link>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141357#M4327</link>
    <description>&lt;P&gt;Please check back for more updates. While it is the case that a default Splunk installation will not be vulnerable to shellshock, we hope to provide more specific information warning you where you could be vulnerable if you install or configure shell scripts. If you are in this situation or are not sure, you may want to simply patch bash.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Sep 2014 23:55:04 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2014-09-26T23:55:04Z</dc:date>
    <item>
      <title>Unix shell shock vulnerability: Is Splunk web or mgt port vulnerable to attacks when running on Unix system with shell shock vulnerability?</title>
      <link>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141354#M4324</link>
      <description>&lt;P&gt;Regarding the shell shock vulnerability, and assuming the host where Splunk or Splunkforwarder is running has the shell shock vulnerability, is it possible to invoke the vulnerability via the splunkweb(8000) or mgt ports(8089)?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html"&gt;http://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2014/09/24/finding-shellshock-cve-2014-6271-with-splunk-forwarders/"&gt;http://blogs.splunk.com/2014/09/24/finding-shellshock-cve-2014-6271-with-splunk-forwarders/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 17:52:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141354#M4324</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2014-09-25T17:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unix shell shock vulnerability: Is Splunk web or mgt port vulnerable to attacks when running on Unix system with shell shock vulnerability?</title>
      <link>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141355#M4325</link>
      <description>&lt;P&gt;No it is not. Splunk will only call external processes in response to user actions in:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;A custom search command. These run under the Splunk python interpreter, not bash, and do not allow arbitrary specification of environment variables.&lt;/LI&gt;
&lt;LI&gt;A scripted lookup. This operates the same as a custom search command, with the addition that it may run Perl as well as python&lt;/LI&gt;
&lt;LI&gt;An alert action. This may be a shell script, but it must be specified by path and must reside in a specific location (not an arbitrary command or command line), and the user can not specify environment variable to pass to it.&lt;/LI&gt;
&lt;LI&gt;A scripted or modular input. These may be shell scripts, they must be specified by path and must reside in a specific location (not an arbitrary command or command line), and the users can not specify environment variables to pass to them.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In all cases, the external program must be placed in specific locations on the system by an administrator. By default, there are no scripts or programs that invoke bash in current or recent versions of Splunk. The administrator can of course create vulnerabilities by placing and allowing access to dangerous programs. But the shellshock bash vulnerability can not be invoked.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 20:33:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141355#M4325</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-09-25T20:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unix shell shock vulnerability: Is Splunk web or mgt port vulnerable to attacks when running on Unix system with shell shock vulnerability?</title>
      <link>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141356#M4326</link>
      <description>&lt;P&gt;Thanks for the quick response!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 21:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141356#M4326</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2014-09-25T21:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unix shell shock vulnerability: Is Splunk web or mgt port vulnerable to attacks when running on Unix system with shell shock vulnerability?</title>
      <link>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141357#M4327</link>
      <description>&lt;P&gt;Please check back for more updates. While it is the case that a default Splunk installation will not be vulnerable to shellshock, we hope to provide more specific information warning you where you could be vulnerable if you install or configure shell scripts. If you are in this situation or are not sure, you may want to simply patch bash.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2014 23:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141357#M4327</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-09-26T23:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unix shell shock vulnerability: Is Splunk web or mgt port vulnerable to attacks when running on Unix system with shell shock vulnerability?</title>
      <link>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141358#M4328</link>
      <description>&lt;P&gt;Updated guidance from Splunk: &lt;A href="http://www.splunk.com/view/SP-CAAANJN"&gt;http://www.splunk.com/view/SP-CAAANJN&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 20:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Unix-shell-shock-vulnerability-Is-Splunk-web-or-mgt-port/m-p/141358#M4328</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2014-09-29T20:50:35Z</dc:date>
    </item>
  </channel>
</rss>

