Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Symantec Web Gateway Vulnerabilities

Updated: 10 Jul 2010 | 2 comments
Earth Juice's picture
0 0 Votes
Login to vote

Hi,

Just installed our new Symantec Web Gateway model 8450.  It was a snap to install, make operational and begin monitoring traffic and blocking the bad guys.

Now I've run a network vulnerability scan on the unit and it identified two problems:

1.) Squid versions 2-4 Stable 6 is vulnerable (can I upgrade this?)
2.) mod_ssl older than 2.8.7 have a buffer over which could allow users to gain a shell remotely.

Also, the SSL certificate is issued by MI5Networks; is there some way to install a proper certificate?

Thanks in advance,

steve

discussion Filed Under:

Comments

KevK76's picture
21
Oct
2009
1 Vote +1
Login to vote

Web Gateway vulnerabilities

Hi Steve,

My understanding is you are working with Support to verify if there are any issues here, is that correct?

Thanks,

Kevin

Earth Juice's picture
08
Jan
2010
0 Votes 0
Login to vote

Sorry for the tardy reply

Sorry for the tardy reply kevin,

Yes, called support, vulnerabilities were patched, both symantec and GFI updates.  There is no support for altering the SSL certificate.

Take care,

steve