"Http Vulnerability on Raspberry Pi Detected" after installing PiHole

Hi, First off - Pi-Hole is awesome!

Secondly I have an issue that appears to be with the Pi-Hole (and I beg your indulgence, I am a Pi Noob). I have been using Pi-Hole for a while now with no problems however I recently started using a tool called "Bitdefender Home Scanner", and once using it and doing a scan it is was showing the Pi as "Http Vulnerability on Raspberry Pi Detected (risk Medium)".

I ran updates on the pi but the message was still showing despite running a new scan it was still showing the above so I started from scratch and installed Raspian (8 Jessie) all over again using NOOBS and the message was gone. I have since setup Pi-Hole again on the pi and the message has come back.

I have updated the pi and done some research on the internet, the two recent exploits I found were Dirtycow and Bashmash and to my knowledge my pi is 'patched' against them, can anyone suggest anything? (I have googled extensively and looked on the bitdefender site and could not find anything useful beyond the fact that their scanner is presenting a possible issue with the pi and offering to sell me a bitdefender Box to secure all my devices).

Am I worrying over a false positive or is there something additional I need to do?

Thanks in advance.

Screenshot here: https://drive.google.com/open?id=0BwiHNJ0NBj9HZzdIWkY5cDIxbkk

I assume you operate your Raspberry Pi behind a router (having a firewall)? If this is the case, then this is in fact not a security issue, since the Raspberry is not even reachable from the outside world.

It is as simple as that and only gets more complicated if you configure firewall exceptions in your router.

Hi DL6ER, yes I do have a router firewall and thank you for the reassuring reply :slight_smile:

At this point now I'm just curious as I've got another Pi that does not have PiHole (a Pi 1 but same Raspbian 8 Jessie) and it is not showing the HTTP vulnerability.

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.