<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack in RUCKUS Cloud</title>
    <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31244#M590</link>
    <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5f9169f549d3ca752488d141" style=""&gt;@syamantak_omer&lt;/A&gt; could you tell me 9001 is filebeat service???&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jul 2021 12:48:57 GMT</pubDate>
    <dc:creator>li_xiang</dc:creator>
    <dc:date>2021-07-06T12:48:57Z</dc:date>
    <item>
      <title>SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31235#M581</link>
      <description>&lt;P style="margin: 0;"&gt;I am a security researcher from Baidu，Recently, we have detected a large number of hacking incidents from ddos attacks initiated on the UDP9001 port on the SmartZone-100 device. Great harm!!!&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Refer to my screenshot for details.my phone number is 18903860673&lt;/P&gt;
&lt;P style="margin: 0;"&gt;My email address is 18903860673@163.com， I come from Baidu in China，Hope you guys get back to me as soon as possible，&lt;/P&gt;
&lt;DIV style="text-align: center;"&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_60e2e826343e2b0bb01b8590_219bd35fad14c5417a7d39494614700d_1-26b24858-5030-47b4-b43a-b44b450c4a75-46734060.png"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2300i0DEB2F48CB1EC832/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_60e2e826343e2b0bb01b8590_219bd35fad14c5417a7d39494614700d_1-26b24858-5030-47b4-b43a-b44b450c4a75-46734060.png" alt="Image_ images_messages_60e2e826343e2b0bb01b8590_219bd35fad14c5417a7d39494614700d_1-26b24858-5030-47b4-b43a-b44b450c4a75-46734060.png" /&gt;&lt;/span&gt;
&lt;/DIV&gt;
&lt;DIV style="text-align: center;"&gt;
&lt;DIV style="text-align: center;"&gt;
&lt;DIV style="text-align: center;"&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_60e2e826343e2b0bb01b8590_f0303439659a2da30844ab8530b7fbb5_4-bf56df6d-8c4f-4824-a102-978858c41c8a-49504623.png"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2301i842108FA260868F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_60e2e826343e2b0bb01b8590_f0303439659a2da30844ab8530b7fbb5_4-bf56df6d-8c4f-4824-a102-978858c41c8a-49504623.png" alt="Image_ images_messages_60e2e826343e2b0bb01b8590_f0303439659a2da30844ab8530b7fbb5_4-bf56df6d-8c4f-4824-a102-978858c41c8a-49504623.png" /&gt;&lt;/span&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV style="text-align: center;"&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_60e2e826343e2b0bb01b8590_08d613990b078e9c2e92d2c3c5c6df48_5-37ecab71-5b48-4656-8707-bac7a4541638-50428144.png"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2302iEB1063175B26D3F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_60e2e826343e2b0bb01b8590_08d613990b078e9c2e92d2c3c5c6df48_5-37ecab71-5b48-4656-8707-bac7a4541638-50428144.png" alt="Image_ images_messages_60e2e826343e2b0bb01b8590_08d613990b078e9c2e92d2c3c5c6df48_5-37ecab71-5b48-4656-8707-bac7a4541638-50428144.png" /&gt;&lt;/span&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:08:22 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31235#M581</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-05T11:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31236#M582</link>
      <description>&lt;P style="margin: 0;"&gt;Hello li_xiang,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;We use port 9001 for Elastic Search DB update and also sync with member node in the vSZ/SZ Cluster. Please feel free to report a case with us for further investigation. Also make sure to mention the current firmware running on the SZ.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Regards,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Parikshith&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:18:19 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31236#M582</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-07-05T11:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31237#M583</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5fa5ac8235f40c122b57116d" style=""&gt;@parikshith_nagaraj_aa0004&lt;/A&gt; Can you tell me the business situation? What is the relationship between SmartZone-100 and ES, and why will ES services be deployed on SmartZone-100? At present, these SmartZone-100 devices still have problems. Port 9001 can accept any UDP request to respond to very large data packets, which will be used by hackers.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:39:54 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31237#M583</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-05T11:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31238#M584</link>
      <description>&lt;P style="margin: 0;"&gt;Hi &lt;A href="https://forums.ruckuswireless.com/users/60e2e604343e2b0bb01b8587" style=""&gt;@li_xiang,&lt;/A&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;As per the design, ES helps fetch data from Cassandra DB and present it to Web GUI. Also maintains the DB between different SZ Nodes in the cluster.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;As suggested please feel free to report a case for further investigation.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Regards,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Parikshith&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:06:51 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31238#M584</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-07-05T12:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31239#M585</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5fa5ac8235f40c122b57116d" style=""&gt;@parikshith_nagaraj_aa0004&lt;/A&gt; Is the ES deployed on SZ an ES service or a plug-in&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:15:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31239#M585</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-05T12:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31240#M586</link>
      <description>&lt;P style="margin: 0;"&gt;&lt;A href="https://forums.ruckuswireless.com/users/60e2e604343e2b0bb01b8587" style=""&gt;@li_xiang, &lt;/A&gt;Yes, we have ES Service deployed on SZ. If you run "Show service" from CLI, should be able to see the status.&lt;/P&gt; 
&lt;P style=" text-align: left;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Regards,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Parikshith&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:19:20 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31240#M586</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-07-05T12:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31241#M587</link>
      <description>&lt;P style="margin: 0;"&gt;Hi Li,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Our security team has been notified to review this.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 21:22:12 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31241#M587</guid>
      <dc:creator>syamantakomer</dc:creator>
      <dc:date>2021-07-05T21:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31242#M588</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5fa5ac8235f40c122b57116d" style=""&gt;@parikshith_nagaraj_aa0004&lt;/A&gt;&amp;nbsp; udp9001 is filebeat plugin？？？&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 07:28:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31242#M588</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-06T07:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31243#M589</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5fa5ac8235f40c122b57116d" style=""&gt;@parikshith_nagaraj_aa0004&lt;/A&gt; could you tell me the Software version of filebeat？&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 07:30:21 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31243#M589</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-06T07:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31244#M590</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5f9169f549d3ca752488d141" style=""&gt;@syamantak_omer&lt;/A&gt; could you tell me 9001 is filebeat service???&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 12:48:57 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31244#M590</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-06T12:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31245#M591</link>
      <description>&lt;P style="margin: 0;"&gt;&lt;A href="https://forums.ruckuswireless.com/users/60e2e604343e2b0bb01b8587" style="text-decoration: 'none';" data-id="60e2e604343e2b0bb01b8587" data-username="li_xiang"&gt;@li_xiang&lt;/A&gt;&lt;SPAN class="dummy"&gt; and&amp;nbsp;&lt;A href="https://forums.ruckuswireless.com/users/5fa5ac8235f40c122b57116d" style="text-decoration: 'none';" data-id="5fa5ac8235f40c122b57116d" data-username="parikshith_nagaraj_aa0004"&gt;@parikshith_nagaraj_aa0004&lt;/A&gt;&lt;SPAN class="dummy"&gt; &lt;/SPAN&gt;and &lt;A href="https://forums.ruckuswireless.com/users/5f9169f549d3ca752488d141" style="text-decoration: 'none';" data-id="5f9169f549d3ca752488d141" data-username="syamantak_omer"&gt;@syamantak_omer&lt;/A&gt;&lt;SPAN class="dummy"&gt; &lt;SPAN&gt;:&amp;nbsp; you're still able to read and access this thread after we shifted it private, correct?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN&gt;Allan.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 18:47:11 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31245#M591</guid>
      <dc:creator>grodog-prod</dc:creator>
      <dc:date>2021-07-06T18:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31246#M592</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/5f9169f249d3ca752488c5cc" style=""&gt;@allan_grohe&lt;/A&gt; Yes, we can access ip and port through UDP protocol and receive excessive response packets. Can you tell me what service is opened on port 9001? It should not be es, but filebeat? What is the specific service?&lt;/P&gt; 
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 01:40:35 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31246#M592</guid>
      <dc:creator>li_xiang</dc:creator>
      <dc:date>2021-07-07T01:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31247#M593</link>
      <description>&lt;P style="margin: 0;"&gt;&lt;A href="https://forums.ruckuswireless.com/users/5f9169f549d3ca752488d141" style="text-decoration: 'none';" data-id="5f9169f549d3ca752488d141" data-username="syamantak_omer"&gt;@syamantak_omer&lt;/A&gt;&lt;SPAN class="dummy"&gt; &lt;SPAN&gt;and &lt;A href="https://forums.ruckuswireless.com/users/5fa5ac8235f40c122b57116d" style="text-decoration: 'none';" data-id="5fa5ac8235f40c122b57116d" data-username="parikshith_nagaraj_aa0004"&gt;@parikshith_nagaraj_aa0004&lt;/A&gt;&lt;SPAN class="dummy"&gt; can help you better then me on that front, &lt;A href="https://forums.ruckuswireless.com/users/60e2e604343e2b0bb01b8587" style="text-decoration: 'none';" data-id="60e2e604343e2b0bb01b8587" data-username="li_xiang"&gt;@li_xiang&lt;/A&gt;&lt;SPAN class="dummy"&gt;---I'm not technical in our products like they are!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN class="dummy"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN&gt;&lt;SPAN class="dummy"&gt;&lt;SPAN class="dummy"&gt;Allan.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 15:28:12 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31247#M593</guid>
      <dc:creator>grodog-prod</dc:creator>
      <dc:date>2021-07-07T15:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: SmartZone-100 product has security vulnerabilities.Hackers can use udp9001 port 
to launch ddos reflection amplification attack</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31248#M594</link>
      <description>&lt;P style="margin: 0;"&gt;Hi All,&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;This vulnerabilities has been fixed by our engineering team.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Refer the security advisory from the below link.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;A href="https://support.ruckuswireless.com/security_bulletins/312" target="_blank" rel="noopener"&gt;https://support.ruckuswireless.com/security_bulletins/312&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 16:40:03 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Cloud/SmartZone-100-product-has-security-vulnerabilities-Hackers-can/m-p/31248#M594</guid>
      <dc:creator>syamantakomer</dc:creator>
      <dc:date>2021-07-21T16:40:03Z</dc:date>
    </item>
  </channel>
</rss>

