CVE-2014-6271 Shellshocked
It's a good thing we are naming all of our vulnerabilities now; it's easier to keep track of them. I haven't seen an official designation for CVE-2014-6271, but Shellshock seems appropriate. This ...
Published Sep 25, 2014
Version 1.0Jeff_Costlow_10
Historic F5 Account
Joined January 26, 2005
Jeff_Costlow_10
Historic F5 Account
Joined January 26, 2005
Network_Operat2
Sep 26, 2014Nimbostratus
1) What about APM, used to check user certificates before passing the traffic on? That process is hosted by the F5 directly, and is exposed to anonymous users.
2) To all: ... check your www logs for this string: () { - saw lots of attempts to install wow1 last night. If your F5 hosted server is at Bash enabled and unpatched... it may be already owned.