Nagios Vulnerability to solarwinds

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
ITOMB_IMT
Posts: 181
Joined: Wed Oct 17, 2018 12:55 pm

Nagios Vulnerability to solarwinds

Post by ITOMB_IMT »

"Good Morning ,
As you have seen in the media, FireEye and Solarwinds corporations were the targets of a suspected nation-state sponsored cyberattack. We wanted to confirm that Nagios XI is not vulnerable per this known exploit."

Thanks,
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Nagios Vulnerability to solarwinds

Post by scottwilkerson »

Nagios XI is not at all affected by this at all, The backdoor came from SolarWinds.Orion.Core.BusinessLayer.dll is a SolarWinds digitally-signed component of the Orion software.

This is specific to Solarwinds Orion software, and also affects Windows systems, Nagios XI only runs on Linux.

Here is a detailed account of the SUNBURST Backdoor
https://www.fireeye.com/blog/threat-res ... kdoor.html
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
Locked