Control Compliance Suite

 View Only
  • 1.  Shellshock - ccsvm not reporting vulnerabilities

    Posted Sep 29, 2014 06:51 AM

    We are using ccsvm to scan assets for the Shellshcok vulnerability and although the latest set of scanning templates have been uploaded to our engines, when scanned the vulnerabilities are not discovered.  Is anyone else experiencing the same?  We have verified the Linux servers being scanned are vulnerable.



  • 2.  RE: Shellshock - ccsvm not reporting vulnerabilities

    Posted Oct 01, 2014 03:19 AM

    kindly confirm whether you are doing credential scan or blackbox scan.



  • 3.  RE: Shellshock - ccsvm not reporting vulnerabilities

    Posted Oct 01, 2014 10:27 AM

    Hi,

    Just want to confirm whether you are using the default templates or you created a new scan template for shellshock?



  • 4.  RE: Shellshock - ccsvm not reporting vulnerabilities

    Posted Oct 02, 2014 03:44 AM

    I noticed this as well, it was working and now it's not, I've triple checked all my settings. 2 days ago it was detecting it, now the same scan does not, and I've confirmed the assets I'm targeting are not patched yet.



  • 5.  RE: Shellshock - ccsvm not reporting vulnerabilities

    Posted Oct 02, 2014 04:00 AM

    We are using a blackbox scan, however, we have been advised that we need to run these scans with credentials.  This is not ideal as we do not necessarily know the credentials of all the Linux estate within our organisation??



  • 6.  RE: Shellshock - ccsvm not reporting vulnerabilities

    Posted Oct 02, 2014 10:45 AM

    FYI - and I'm running credentialed, template and custom scan and neither detect it any longer (they are not patched).



  • 7.  RE: Shellshock - ccsvm not reporting vulnerabilities

    Posted Oct 04, 2014 11:45 AM

    @IM140.6: I think you have not configure the scan template properly to scan for shellshock vulnerbaility.

    Simple way to create shellshock template is copy a full audit template and remove all the vulnerabilities selected in By categories and By check types and search for CVE-2014-6271 in by individual check and select all the vulnerability check and save the template. Now scan with this template for shellshock scanning.

    Create a new scan template while following above mentioned steps and try to scan for shellshock vulnerability.