Vulnerability Development mailing list archives

Re: network appliance...


From: bifrost () MINIONS COM (Tom)
Date: Wed, 12 Apr 2000 09:52:47 -0700


On Mon, 10 Apr 2000, JT wrote:
has anyone heard of vulnerabilities in the Network Appliance base
operating systems?

I've heard of a couple, but not for a few months.
Check out the Securityfocus archives...

they're the company that makes large filer head
systems and my company is considering buying one. the operating system
is unix or unix based but an nmap scan on known open ports in
demonstration showed absolutely nothing - no operating systems id
either. i was curious as to whether this is really as safe as it seems...

They're BSD based, Netapp created their own embedded system for the
filer, which is based on Alpha hardware.
You can actually login to them, run ps, ls, df all kinds of fun stuff.
The biggest problem with them is that they need an administrative host,
and if you pick a bad platform and don't secure it, you could be in
trouble.


Current thread: