Page 3 of 3 FirstFirst 123
Results 21 to 26 of 26
  1. #21
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    25,859

    Default

    Quote Originally Posted by oj88 View Post
    This.

    It'll be nice to have this granularity. The "nuke em" option, I agree, is overkill when all that's needed is to be able to manually purge entries beyond a certain time.
    Code:
    /usr/share/untangle/bin/reports-clean-tables.py -d "postgresql" 7
    You know... because Untangle apparently can't use their own scripts. The above dumps reports down to the last 7 days, change the 7 to fit your needs.

    I don't... understand why they went with the scorched Earth approach.
    Last edited by sky-knight; 04-28-2021 at 08:14 PM.
    oj88 and jcoehoorn like this.
    Rob Sandling, BS:SWE, MCP
    NexgenAppliances.com
    Phone: 866-794-8879 x201
    Email: support@nexgenappliances.com

  2. #22
    Untangle Ninja
    Join Date
    May 2008
    Posts
    1,523

    Default

    The beta security is already out of date. https://lists.debian.org/debian-secu.../msg00090.htmlDebian is pushing the update out to buster now. We will be lucky to see it in the release candidate or the release.

  3. #23
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    25,859

    Default

    Quote Originally Posted by donhwyo View Post
    The beta security is already out of date. https://lists.debian.org/debian-secu.../msg00090.htmlDebian is pushing the update out to buster now. We will be lucky to see it in the release candidate or the release.
    Umm... no?

    Untangle doesn't use Bind for DNS, it uses DNSMasq. Bind can't be vulnerable if it's not installed!
    Rob Sandling, BS:SWE, MCP
    NexgenAppliances.com
    Phone: 866-794-8879 x201
    Email: support@nexgenappliances.com

  4. #24
    Untangle Ninja
    Join Date
    May 2008
    Posts
    1,523

    Default

    HTML Code:
    [root @ homeuntangle] ~ # dpkg -l |grep bind
    ii  bind9-host                              1:9.11.5.P4+dfsg-5.1+deb10u3                                   amd64        DNS lookup utility (deprecated)
    ii  libbind9-161:amd64                      1:9.11.5.P4+dfsg-5.1+deb10u3                                   amd64        BIND9 Shared Library used by BIND
    ii  libwbclient0:amd64                      2:4.9.5+dfsg-5+deb10u1                                         amd64        Samba winbind client library
    ii  python-ldb                              2:1.5.1+really1.4.6-3+deb10u1                                  amd64        Python bindings for LDB
    ii  python-pycurl                           7.43.0.2-0.1                                                   amd64        Python bindings to libcurl
    ii  python-samba                            2:4.9.5+dfsg-5+deb10u1                                         amd64        Python bindings for Samba
    ii  python-selenium                         3.14.1+dfsg1-1                                                 all          Python bindings for Selenium
    ii  python-talloc:amd64                     2.1.14-2                                                       amd64        hierarchical pool based memory allocator - Python bindings
    ii  python-tdb                              1.3.16-2+b1                                                    amd64        Python bindings for TDB
    ii  python3-pycurl                          7.43.0.2-0.1                                                   amd64        Python bindings to libcurl (Python 3)
    ii  winbind                                 2:4.9.5+dfsg-5+deb10u1                                         amd64        service to resolve user and group information from Windows NT servers
    Must have changed for 16.3.
    Code:
    Build: 16.3.0.20210419T114213.6c60930bfe-1buster
    Kernel: 4.19.0-11-untangle-amd64
    Last edited by donhwyo; 05-03-2021 at 06:13 AM.

  5. #25
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    25,859

    Default

    And if you run service --status-all you'd notice not a single mention of bind anywhere.

    That's an artifact of a default Debian installation, it's not actually running so it cannot be exploited.

    Furthermore, if you read your own output you'd notice that is the Bind9 DNS CLIENT, not the Bind9 DNS SERVER. Which is what those vulnerabilities reference.

    I repeat, that list of CVs do not apply to Untangle.
    Rob Sandling, BS:SWE, MCP
    NexgenAppliances.com
    Phone: 866-794-8879 x201
    Email: support@nexgenappliances.com

  6. #26
    Newbie
    Join Date
    Sep 2020
    Posts
    12

    Default

    wow still no 2fa for console or letsencrypt support....

Page 3 of 3 FirstFirst 123

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2