Outdated NGINX SERVER

Robust

Cadet
Joined
Jul 1, 2022
Messages
3
Hi,

After I do the Pentest, has found Outdated NGINX SERVER on FreeNAS.
I used FreeNAS-9.10.2
Why it happens and any solutions/steps that I need to do for solve this issue?

Thanks
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,700
Why it happens and any solutions/steps that I need to do for solve this issue?
You're using a version that's many years old and has not received new updates in years either... no surprises that some of the component products are old and unsupported/vulnerable.

In any case you shouldn't be exposing a FreeNAS server to any unprotected network.

If you want to improve your "up to date-ness" you'll need to upgrade to a supported version of FreeNAS (which is now TrueNAS CORE).

Even after that, a Pentest isn't going to tell you anything interesting since you still shouldn't expose a TrueNAS server to an unprotected network.
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
FreeNAS-9.10.2
This release is six years old, and the product has seen three major releases (and countless minor releases) since then--of course nginx is outdated; everything else likely is too.
any solutions/steps that I need to do for solve this issue?
"Upgrade to a newer version of Free/TrueNAS" seems like obvious enough advice that you wouldn't even need to ask about it, but apparently it wasn't. Is there a reason that solution didn't immediately suggest itself to you?
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
I just want to point out that posting the same thing after the weekend is not likely to change the answers you get. It is, however, likely to make moderators grumpy. Your installed version of FreeNAS is not getting any younger, so please update it instead of posting duplicate threads.
 
Joined
Oct 22, 2019
Messages
3,641
I found some outdated software and vulnerabilities when I ran a pentest on Ubuntu 12.04. I'm drafting a detailed report to send to Canonical Ltd. by tomorrow or Wednesday.
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
There may be language issues here. @Robust, no, this has nothing to do with any firmware. If you don't want to be running an ancient version of your file server appliance (with its included ancient version of a web server), upgrade to a less-ancient (or preferably a current) version of the file server appliance.

As I posted nearly a week ago, this should have been blindingly obvious. Why wasn't it?
 
Top