Enjoying this fully patched Ivanti Pulse Connect box (yes, the kernel has dirty in it)
Linux version 2.6.32-00366-gsd3b182-dirty - December 2009
curl 7.19.7 2009-11-04 (14 years)
openssl 1.0.2n-fips 2017-12-07 (6 years)
perl 5.6.1 2001-04-09 (23 years)
psql 9.6.14 2019-06-20 (5 years)
cabextract 0.5 2001-08-20 (22 years)
ssh 5.3p1 2009-10-01 (14 years)
unzip 6.00 2009-04-29 (15 years)
US Federal agencies plugging their Ivanti boxes back into the internet after factory resetting them
TIL it doesn’t matter what me and @wdormann think, it’s only real when people read about it on Hacker News.
@dwm @GossiTheDog Wept? More like, cried a river.
@GossiTheDog lol cabextract
@GossiTheDog@cyberplace.social Is that PSV or ISV?
@GossiTheDog The 1/31 directive should have ended after this sentence:
@GossiTheDog I’m only here for the logos
@GossiTheDog I feel like there's an awful lot of stuff Ivanti has acquired over the years that's probably similar.
@GossiTheDog come on now, that’s what vendors refer to as a fully hardened appliance!
@deepthoughts10 @GossiTheDog fully fossilized appliance
@GossiTheDog 2.6.32, the golden linux kernel
@GossiTheDog stop worrying, it's FIPS certified crypto! (crapto?)
@GossiTheDog note the attribution license doc mentions a bunch of python modules, some frontend and some backend. noirbizarre/flask-restplus, rptlab/reportlab (PDF gen library), scikit-learn/scikit-learn (Python machine learning library using SciPy). Python is probably on there somewhere.
https://help.ivanti.com/ps/help/en_US/ICS/22.x/22.6R2/ICS%20Attributions.pdf
#ivanti #ivantivpn
@GossiTheDog looks much like the stack used by $big.SaaS org to host vast amounts of customer email did, 10y ago. (I'm sure they've fixed all that by now. Right, kids?)
@GossiTheDog but the important thing is that SBOMs are too hard, and no one needs them.
@GossiTheDog that's the latest version of unzip https://sourceforge.net/projects/infozip/files/UnZip%206.x%20(latest)/UnZip%206.0/
If it ain't broke...
@GossiTheDog What version of the appliance comes with the 2.6 Linux kernel?
22.3R1 runs 4.15.18.34.
@wdormann @GossiTheDog Ivanti does publish a list of all the third party software in each version, just change the URL for whatever release:
https://help.ivanti.com/ps/help/en_US/ICS/9.1RX/9.1R18-Connect-Secure-Attributions.pdf