Forum Discussion
Question regarding iHealth
Why would you think it was shellshock? Do you allow non-admins to login? Or run CGI's on publicly available web servers direct on the BigIP (i.e. The admin GUI).
Shellshock isn't a virus, or trojan. It's a bug in the bash shell where it interpret various things as code (e.g. ENV vars) and evaluates them... Which can lead to unintended consequences. IF someone has access to the BigIP admin interfaces bash shell, I'm not sure if there's any CGI on the GUI that would be vulnerable. Not seem any indication. But an attacker needs access anyway. And normally you wouldn't allow anyone except trusted admins access to the admin interfaces in the first place...
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com