governa, to random
@governa@fosstodon.org avatar

Alert: Over 178,000 Firewalls Potentially Vulnerable to Exploits โš ๏ธ ๐Ÿ”ฅ

https://thehackernews.com/2024/01/alert-over-178000-sonicwall-firewalls.html

BishopFox, to infosec

SonicWall next-gen firewall (NGFW) series 6 and 7 devices are affected by 2 DoS #vulnerabilities that can lead to remote code execution (RCE): #CVE-2022-22274 and CVE-2023-0656. Bishop Fox research revealed that these issues are fundamentally the same, but exploitable at different HTTP URI paths. Read more & download our test script at our blog.

https://bfx.social/47Hcdzj

#SonicWall #infosec #exploitdevelopment

video/mp4

bouncyhat, to ReverseEngineering

When we're doing vuln hunting on internet appliances, we often want a shell in order to figure out what's going on. For the F5 research we were lucky, you could just SSH into the box and immediately get access to relevant config files and binaries. Lots of other appliances don't like to give out that access, they might give some kind of restricted/custom shell, or maybe they just don't expose anything at all.

In order to get around this, we'll often grab VM images and then boot from a live cd / alternate linux install and mount the disks. More recent Sonicwall appliances prevent this behavior, however. Their disk partitions are all LUKS encrypted, which prevents nosey researchers like myself from being able to mount them via another OS that doesn't have the encryption keys.

What's interesting though, is that if you boot from the base image (as intended), it just works. GRUB does have a mechanism for embedding decryption keys into the boot process, but this often means just leaving the decryption key in the boot partition, which is pretty easy to grab. This is not what Sonicwall NSV appliances do.

I got to spend a fun week diving into how GRUB works in order to figure out just what on earth was happening here - feel free to read about it at https://www.praetorian.com/blog/sonicwall-custom-grub-luks-encryption/.

The TL;DR is that Sonicwall modified their GRUB bootloader to perform decryption key derivation based off of the partition metadata. This is very much NOT default GRUB behavior (as far as I'm aware), so someone at Sonicwall went out of their way to bake this into the bootloader. It was a fun RE experience though, definitely got to learn a lot!

jgreig, to random
@jgreig@ioc.exchange avatar

US Radiology is paying a $450,000 fine in an agreement with New York State's Attorney General after a 2021 ransomware attack caused in part by the company's failure to address a SonicWall vulnerability

https://therecord.media/new-york-attorney-general-fines-radiology-firm-after-ransomware-attack

FoW, to infosec Korean
@FoW@netsphere.one avatar

์ธํ”„๋ผ ๋ฒค๋”์—์„œ ๋‹ค์‹œ ๋…๋ฆฝ์„ฑ์„ ๋˜์ฐพ์•„๊ฐ€๋Š” ์ •๋ณด๋ณด์•ˆ ๋ฒค๋”๋“ค
๊ทธ๊ฐ„ ํ•˜๋“œ์›จ์–ด ๊ธฐ๋ฐ˜ ๋ฒค๋”๋“ค์ด ์ •๋ณด๋ณด์•ˆ ๋ฒค๋”๋ฅผ ์„œ๋กœ ์ธ์ˆ˜ํ–ˆ๊ณ  ์‹œ๋„ˆ์ง€๋ฅผ ๋‚ด๋ณด๋ ค ํ–ˆ์ง€๋งŒ ์ •๋ณด๋ณด์•ˆ ๋ฒค๋”๋งŒ ๋ถ€์ˆด์ง€๋Š” ๊ฒฐ๊ณผ๊ฐ€ ๋งŽ์•˜์–ด์š”. ๊ฒฐ๊ตญ ๋‹ค์‹œ ๋ถ„๋ฆฌํ•˜๋Š” ์ˆ˜์ˆœ ๊ฐ™์•„์š”.
์†Œ๋‹‰์›”์ด ๋ธ์—์„œ ๋ถ„์‚ฌํ•œ ์ดํ›„๋กœ ๋‹ค์‹œ ์†”๋ฃจ์…˜ ์ฒด๊ณ„๋ฅผ ๊ฐ–์ถ”๋ฉฐ ์„ฑ์žฅ์— ํ™œ๊ธฐ๊ฐ€ ๋„๋‚˜ ๋ด์š”. ์—…๊ณ„ ํƒ‘ ๋ฒค๋” ์—”์ง„์„ ์ ๊ทน ๊ณ„์•ฝํ•ด์„œ๋ผ๋„ ์ถฉ์‹คํ•˜๊ฒŒ ๊ตฌ์ƒ‰์„ ๋งž์ถ”๋Š” ๋ชจ์Šต์ด ์ธ์ƒ๊นŠ๋„ค์š”.
์นด๋ณธ๋ธ”๋ž™ ๋˜ํ•œ ๋ธŒ๋กœ๋“œ์ปด์— ์ธ์ˆ˜๋˜๋ฉด์„œ, ์ธ์ˆ˜ ์ „์ฒ˜๋Ÿผ ์ •๋ณด๋ณด์•ˆ ๋ณธ์—ฐ์— ์ง‘์ค‘ํ•  ์ˆ˜ ์žˆ๋„๋ก ์Šน์ธ ๋ฐ ํˆฌ์ž ๋ฐ›์•„ ์กฐ์ง ํ™•์žฅ ์ค‘์ด๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ์‹œ๋งŒํ… ์ผ€์ด์Šค๋ฅผ ์‹ ๊ฒฝ์“ฐ๋‚˜ ์‹ถ์Šต๋‹ˆ๋‹ค. ๋ธŒ๋กœ๋“œ์ปด ์ธ์ˆ˜์— ์˜คํžˆ๋ ค ํ™”์ƒ‰์ด ๋„๋„ค์š”.

zorangrbic, (edited ) to random

Fun.

with 2yr license just arrived. For the rest of the story, it's important to note that it's a new device with a price of 1.346eur. A bit less in US dollar.

And, what do you know: Even that doesn't save you from being exposed to a crappy onboarding procedure, a WRONG quick start guide and no hints in the support pages of what could be wrong.

Spent 3,5h trying to understand why the devices wizard (fire him!) didn't want to accept my license.

1/* ->

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • provamag3
  • ethstaker
  • osvaldo12
  • tester
  • GTA5RPClips
  • cubers
  • everett
  • tacticalgear
  • cisconetworking
  • normalnudes
  • anitta
  • Leos
  • megavids
  • lostlight
  • All magazines