Forum Discussion
F5 shellshock with Bash shell.
luyenntk50db,
The iRule is for backend servers that might be vulnerable that are fronted by a big-ip device. The big-ip, via an irule, can prevent the attack vector from reaching the backend servers. This gives you time to patch them.
Sol15629 details the big-ip TMOS versions that are vulnerable, namely the management web gui. If you haven't patched to the non-vulnerable release then you will be vulnerable. Of course bear in mind that, as of a couple of weeks ago, the only exploit was an authenticated one, i.e. an attacked would need admin/root access to the big-ip. Further recommendation is to keep the management network on a private, secure network and if there any any self IPs which are externally accessible then disable 443 access.
Hope this helps,
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com