{"id":52588,"date":"2022-03-11T18:25:33","date_gmt":"2022-03-11T18:25:33","guid":{"rendered":"https:\/\/merikebi.warrenmyers.com\/?p=52588"},"modified":"2022-03-11T18:25:33","modified_gmt":"2022-03-11T18:25:33","slug":"on-using-nmap-to-help-find-tlstorm-affected-devices","status":"publish","type":"post","link":"https:\/\/merikebi.warrenmyers.com\/?p=52588","title":{"rendered":"on using nmap to help find tlstorm-affected devices"},"content":{"rendered":"<p>You may have <a href=\"https:\/\/thehackernews.com\/2022\/03\/critical-bugs-could-let-attackers.html\">heard<\/a> of the recently-discovered\/-published <a href=\"https:\/\/www.armis.com\/research\/tlstorm\/\">TLStorm<\/a> vulnerability that affects &#8211; at least &#8211; <a href=\"https:\/\/www.apc.com\/shop\/us\/en\/categories\/power\/uninterruptible-power-supply-ups-\/network-and-server\/smart-ups\/N-1h89yke\">APC SmartUPS<\/a> devices.<\/p>\n<p>One of the prime issues highlighted is the embedded <a href=\"https:\/\/www.mocana.com\/nanossl-lp\">nanoSSL<\/a> library that APC has used on these systems.<\/p>\n<p>If you want to find out if your system is affected, the following <a href=\"\/\/nmap.org\"><code>nmap<\/code><\/a> except should start you towards a solution:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p><code>for octet in {30..39}; do (nmap -A -T4 192.168.0.$octet > nmap-192.168.0.$octet.out &amp;) ; done<\/code><\/p>\n<\/blockquote>\n<p>This will kick-off <code>nmap<\/code> to run in parallel. When they all finish (you can monitor how many are running using <code>ps aux | grep nmap<\/code>), you can then process the files rapidly thusly:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p><code>grep -i nano nmap*.out<\/code><\/p>\n<\/blockquote>\n<p>If nanoSSL has been found, you&#8217;ll get a listing of all IPs running it (since you cleverly named your files with the IP in the name).<\/p>\n<p>The mitigations you choose to implement have been explained well in the articles linked above, but <em>finding<\/em> these systems can be a pain.<\/p>\n<p>Hope this helps someone <img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/13.1.0\/72x72\/1f642.png\" alt=\"\ud83d\ude42\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\" \/> <\/p>\n<p>from antipaucity https:\/\/antipaucity.com\/2022\/03\/11\/on-using-nmap-to-help-find-tlstorm-affected-devices\/<br \/>\nvia <a href=\"https:\/\/ifttt.com\/?ref=da&#038;site=wordpress\">IFTTT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You may have heard of the recently-discovered\/-published TLStorm vulnerability that affects &#8211; at least &#8211; APC SmartUPS devices. One of the prime issues highlighted is the embedded nanoSSL library that APC has used on these systems. If you want to find out if your system is affected, the following nmap except should start you towards &hellip;<br \/><a href=\"https:\/\/merikebi.warrenmyers.com\/?p=52588\" class=\"more-link pen_button pen_element_default pen_icon_arrow_double\">Continue reading <span class=\"screen-reader-text\">on using nmap to help find tlstorm-affected devices<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[95],"keyring_services":[],"class_list":["post-52588","post","type-post","status-publish","format-standard","hentry","category-blih","tag-antipaucity"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/52588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=52588"}],"version-history":[{"count":1,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/52588\/revisions"}],"predecessor-version":[{"id":52589,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/52588\/revisions\/52589"}],"wp:attachment":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=52588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=52588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=52588"},{"taxonomy":"keyring_services","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fkeyring_services&post=52588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}