This post is more than 5 years old
5 Posts
0
1658
April 9th, 2014 15:00
Any risk of Heartbleed OpenSSL bug with Data Domain 640?
We're currently going through all our SW and HW to see what may be affected by the current Heartbleed OpenSSL bug. I thought only software and Linux servers would be affected, but some of our Cisco hardware is also affected because the software it runs depends on affected versions of the OpenSSL libraries. We have a couple of Data Domain 640's and I wanted to know if they use any of the affected OpenSSL libraries?
No Events found!


PatrickBetts
1 Rookie
•
116 Posts
0
April 9th, 2014 15:00
sw-luke,
DD OS 5.4.1.1 which is the latest GA release uses OpenSSL 0.9.8, so it is not susceptible to the bug found in 1.0.1. Any release up to 5.4.1.1 will use 0.9.8 or lower.
Best Regards,
Patrick
ble1
6 Operator
•
14.4K Posts
•
56.2K Points
0
April 9th, 2014 15:00
Good question, though I'm not worried. My DDOS uses OpenSSH_5.6p1, OpenSSL 0.9.8w 23 Apr 2012. As affected versions are up to 1.0.1 I would say yes. You can find your version of OpenSSL by going to priv mode and typing se ssh -v afterwards. Why I'm not worried? Because my DD is closed system in closed network and there are no credit cards or gateways via mine DD boxes. While I believe DD is affected, I see no hurry to update them. Hype is big and this is because public services dealing with your money (aka credit cards) are affected, but when it comes to DD I fail to see the risk for now.
EDIT: See previous post. It is just 1.0.1 series affected and not up to 1.0.1 as I claimed originally - so no worries.
dynamox
11 Legend
•
20.4K Posts
•
87.4K Points
0
April 9th, 2014 16:00
your DMZ box gets hacked, then from there they start scanning for other vulnerable systems.
ble1
6 Operator
•
14.4K Posts
•
56.2K Points
0
April 10th, 2014 01:00
I don't run DD in DMZ
But even so, DMZ (at least the way we have it) is protected in such way that I see no easy way to get it - especially not using DD. Chances are it is possible, but it would require someone who really is dedicated to this specific task and company. When I think about all those apache servers on OS and applications which are there for years unpatched, this bug seems almost nothing to me.
dynamox
11 Legend
•
20.4K Posts
•
87.4K Points
0
April 10th, 2014 03:00
i wonder what DD uses to give us that fancy Enterprise Manager GUI, tomcat/apache ?
RobertoAraujo1
2 Intern
•
718 Posts
0
May 14th, 2014 09:00
Hi all,
I'd like to invite everyone to join us on Monday, May 19 to our continued Heartbleed discussion: Ask the Expert - Heartbleed: What It Is & How to detect it using RSA Security Analytics Also, make sure to watch our video introduction about Heartbleed detection.
RSVP today to reserve your spot and receive a reminder.
See you there!