Buffalo Forums

Products => Storage => Topic started by: nelsonm on July 06, 2009, 02:49:20 PM

Title: Outdated Apache and OpenSSL on Terastation?
Post by: nelsonm on July 06, 2009, 02:49:20 PM
   

So I've run a security scan on the terastations and it is alerting me that it is running old versions of Apache and OpenSSL which have open and well known vulnerabilities.

 

Is there any way for me to update this software to the latest versions as to get rid of these vulnerabilities and make this hardware "safe"?

I'm guessing it would normally be through a firmware update, but since Buffalo is not likely to provide one, is there an alternate way of doing it?

Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: PCPiranha on July 06, 2009, 09:47:56 PM

 Which terastation?  Always include a model number and firmware version when inquiring about a product!!

Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: nelsonm on July 07, 2009, 08:27:34 AM
   

Terastation II Rackmount


 Model Name: TS-RHTGL/R5 F/W 1.33

Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: Colin137 on July 07, 2009, 03:25:18 PM

It appears that the Apache vulnerabilities are fairly minor... most are regarding potential XSS attack vectors. This can be mitigated by making sure port 80 on the Terastation is not open to the internet.

 

Some of the OpenSSL vulnerabilities are more severe, but again, most are fairly minor.

 

I'll forward a request up to get Apache and OpenSSL updated.

Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: nelsonm on July 07, 2009, 03:28:26 PM
   

Colin,

Thanks.

Is there anyway you can forward a request to update SMB and Kerberos to allow digital packet signing? This is another problem we have.

 

I was told they do not have any plans to update them, I was never given a choice to request it.

Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: Colin137 on July 07, 2009, 03:40:59 PM
I'll request it, but there's no way of knowing if it will get done. From what I've seen, digital packet signing is fairly difficult to implement in a way that works in many different environments.
Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: csfv on September 03, 2009, 12:16:09 PM
   

Any status on updating the apache versions in the buffalo firmware?

 

My Buffalo Terastation (HD-H1 0TGL/R5) is identified on my network as running apache 1.3.33

 

My IT guys say:  

 

apache .lt. 1.3.37 contained a mod_rewrite buffer overflow attack, "RED, URGENT" update or get kicked off the network

apache .lt. 1.3.41 contained multiple vulnerabilities, mod_proxy, mod_imap, mod_status and mod_proxy_ftp, DoS, XSS, "YELLOW, MODERATE" update or get kicked off the network

 

If I want to continue using my drive, I must update to apache 1.3.41 or later.

 

Please advise,

-csfv  

Title: Re: Outdated Apache and OpenSSL on Terastation?
Post by: nelsonm on September 03, 2009, 12:37:43 PM
   I doubt it'll ever get updated.
Browser ID: smf (is_webkit)
Templates: 1: Printpage (default).
Sub templates: 4: init, print_above, main, print_below.
Language files: 1: index+Modifications.english (default).
Style sheets: 0: .
Hooks called: 80 (show)
Files included: 27 - 1055KB. (show)
Memory used: 734KB.
Tokens: post-login.
Queries used: 10.

[Show Queries]