Other: HVR Scheduler fails during tenable vulnerability scan
In HVR 5.7 the hub server is on AIX and client deployed security tool from Tenable -- nessus. This security tool scan all system ports, and during the scan it runs checks against ports that are opened by HVR. This causes the scheduler to shut down and has to manually restarted. Would like HVR to be able to handle these messages without stopping the scheduler service. Here is the output from the scan in the hvr logs:
2022-11-21T14:18:14.240033-07:00 aixcgyapp0041 sudo: service_nessus_xnix : TTY=pts/0 ; PWD=/home/service_nessus_xnix ; USER=root ; COMMAND=/usr/bin/sh -c printf "command_start_%s" "somepassword
"; netstat -a -n; printf "command_done_%s" "somepassword"
2022-11-21T14:18:14.437407-07:00 aixcgyapp0041 sshd[10617226]: error: getsockname failed: A system call received a parameter that is not valid.
2022-11-21T14:18:19.684986-07:00 lnxcgynes0001.cnrl.com ${jndi: ldap://log4shell-generic-kU7EjU5Euq5GSts8EqGR${lower:ten}.w.nessus.org/nessus [w.nessus.org]}
2022-11-21T14:18:19.685123-07:00 aixcgyapp0041 syslog: netstream session 2171fc08 from 172.31.192.80 will be closed due to error: Connection reset by peer [v8.1905.0 try https://www.rsyslog [rsyslog]
.com/e/2165 ]
2022-11-21T14:18:45-07:00: hvrscheduler: F_JC0018: Internal error: Unregistered event 0x247b was unexpectedly received from coprocess '172.31.192.80/4'. The full packet received was '${jndi:ldap://log4shell-generic-pCmX1Ib2XdBlUmOOAdHg${lower:ten}.w.nessus.org/nessus}'. \
F_JJ106C: The previous error occurred while processing event from '172.31.192.80/4'. This object will be disconnected.
2022-11-21T14:18:53-07:00: hvrscheduler: F_JC0018: Internal error: Unregistered event 0x4745 was unexpectedly received from coprocess '172.31.192.80/5'. The full packet received was 'GET / HTTP/1.0\r\n\r\n'. \
F_JJ106C: The previous error occurred while processing event from '172.31.192.80/5'. This object will be disconnected
-
We recommend to whitelist the HVR executable.
Reports like this have been researched before but could not be reproduced.
Mark.
Please sign in to leave a comment.
Comments
1 comment