GNU Bash CVE-2014-6271 attack

Need help? Post your questions here.

Moderator: moderators

GNU Bash CVE-2014-6271 attack

Postby Krosscheck » Thu Dec 11, 2014 9:44 pm

I am running Subsonic 4.9 on a Windows 2008 server and have Symantec Endpoint Protection 12 for virus protection.

About 20-30 times a day, i see this pop up (message below). The traffic is blocked, but I'm wondering if htis is legit or if I should continue to block. Just wanted to see if anyone else noticed this on their subsonic servers.

[SID: 27907] OS Attack: GNU Bash CVE-2014-6271 attack blocked. Traffic has been blocked for this application: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\SUBSONIC\SUBSONIC-SERVICE.EXE
Krosscheck
 
Posts: 20
Joined: Fri Sep 07, 2012 4:34 am

Re: GNU Bash CVE-2014-6271 attack

Postby Fluffhead27 » Sat Jan 03, 2015 8:42 pm

I am having the same thing happen and am curious if this is something I need to worry about as well. From what I can tell, Symantec is doing its job and there is nothing to worry about, but it does worry me that someone is constantly trying to attack my computer via Subsonic.

Some info: http://www.symantec.com/connect/blogs/s ... nerability
- Symantec has created an Intrusion Prevention signature for protection against this vulnerability: 27907 - OS Attack: GNU Bash CVE-2014-6271 (http://www.symantec.com/security_respon ... asid=27907).

I am running Subsonic 5.0 on Windows 7 using Norton Security Suite (Comcast/Xfinity version of Symantec's virus protection).

All the lines with "High" listed in the left column are this attack coming from various IP addresses, all targeting SUBSONIC-SERVICE.EXE
Image

More detailed view
Image
Fluffhead27
 
Posts: 3
Joined: Thu Jun 14, 2012 1:09 pm

Re: GNU Bash CVE-2014-6271 attack

Postby alphawave7 » Sat Jan 03, 2015 11:24 pm

alphawave7
 
Posts: 1042
Joined: Thu Feb 11, 2010 9:54 am


Return to Help

Who is online

Users browsing this forum: No registered users and 13 guests