7 ms·
Palo Alto Networks PAN-OS Zero-Day Exploitation
- aeyes 2y ago> Q. Has my device been compromised by this vulnerability? > Customers are able to open a case in the Customer Support Portal (CSP) and upload a technical support file (TSF) to determine if their device logs match known indicators of compromise (IoC) for this vulnerability. They can't be serious...
- deleted 2y ago[deleted]
- bnjms 2y agoYou want them to share their IoC so the exploit authors can add to the exploit’s mitigations?
- HeatrayEnjoyer 2y agoIoCs are always public
- ok123456 2y agoI'll stick to using a Linux firewall.
- tatersolid 2y agoPaloAlto devices ARE “Linux Firewalls” https://live.paloaltonetworks.com/t5/general-topics/how-to-access-to-linux-mode-in-pa/td-p/64711 https://live.paloaltonetworks.com/t5/general-topics/how-to-a...
- vladvasiliu 2y agoThey probably mean some Linux distro with no crapware on top. Seeing how this exploit seems to be PaltoAlto-specific stuff built on top of the basic OS, GP's approach sounds sensible enough.
- p_l 2y agoThey aren't exactly linux firewalls, even if they run linux as management OS. AFAIK the forwarding engine is custom(ized), and on physical devices some of them offload to FPGA - or at least they used to when I administrated some 2014~2016. The management UI was in PHP :P
- deleted 2y ago[deleted]
- blakesterz 2y agoYou can sort their announcements by CVSS here: https://security.paloaltonetworks.com/?sort=-cvss https://security.paloaltonetworks.com/?sort=-cvss This is their 3rd CVSS 10 in the past 5 years and they've had quite a few more over 9s in the past 5-10 years. I have no idea how that compares to other places like them, maybe they're all like this?
- jiggawatts 2y agoI just saw another vendor’s core network router and firewall product rolled out to replace cloud native routing. It uses public IPs by default with open ports to the Internet to route previously internal-only isolated networks. It uses “military grade” 96 bit encryption (lol), and similarly had a nine-point-something CVE in that endpoint. It was forced upon us because apparently it was vital to encrypt the VM-to-VM intra-cloud traffic that was already mostly HTTPS. This cost merely millions of dollars and broke a bunch of stuff, slowed down that which it didn’t break, and had several brownouts and outages in just a few months since it was rolled out. IT security is mostly snake oil sold by con-men.
- _23sd 2y agoGlobal Protect is up there with Citrix Netscaler and Fortigate SSLVPN in the list of "secure" remote access products that no organization should be using without considering the fact that another easy RCE is going to come out roughly every 12 months and possibly lead to a ransomware incident.
- daghamm 2y agoNot the first widely exploited 0day in GlobalProtect. Can you really consider this a highly secure product? https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=globalprotect&search_type=all&isCpeNameSearch=false https://nvd.nist.gov/vuln/search/results?form_type=Basic&res...
- numpad0 2y agoI understand that these products has market demands from paranoid but not IP networking related businesses, but I never quite understood the fundamental basic premise of Palo Alto, F5 Networks, Fortinet, etc. brands of "MITM TLS firewall" products. These firewall boxes are on-prem white hat Mallory, reverse-reverse-proxying all TLS traffic. And of course the Linux stack it uses has tons of RCEs and misconfigurations. Isn't that just insecure???
- p_l 2y agoIn case of Palo Alto Networks TLS interception wasn't the only, or even main, use in many places. Among reasons one might have seen them was centralised control plane, multipoint VPNs, yes deep-packet inspection (including for simply checking if the expected protocol was running on given traffic), they could be also simply used as pretty advanced router+firewall setup.
- amluto 2y agoIf you have a TLS MITM proxy configured and an attacker pwns the proxy, it’s pretty much game over. Forget access to the internal network: any host that has the MITM proxy’s certificate installed will trust it to view and modify all TLS traffic. This gets a free attack on all web origins without even compromising anything else. AWS console, check. Configuration of other corporate appliances, check. Everyone’s communication tools, check. And you get to replace anything downloaded by anything that doesn’t use certificate pinning.
- p_l 2y agoI'm not saying no. I'm just saying that not everyone used PAN NGFW for MITM proxying, and it's not necessary to enable/configure that to use them for other tasks.
- WirelessGigabit 2y agoCompany I worked at turned on MITM TLS for everything. Suddenly a lot of stuff stopped working, because not every piece of software on my machine uses the OS's certificate store. For example Docker containers who then curl to set up stuff.
- sky_nox 2y ago[flagged]
- wufocaculura 2y agoFrom official advisory at https://security.paloaltonetworks.com/CVE-2024-3400 https://security.paloaltonetworks.com/CVE-2024-3400, I smiled to that one: "If you are unable to apply the Threat Prevention based mitigation at this time, you can still mitigate the impact of this vulnerability by temporarily disabling device telemetry"
- deleted 2y ago[deleted]
- spudlyo 2y ago"Device telemetry collects data about your next-generation firewall or Panorama and shares it with Palo Alto Networks by uploading the data to Cortex Data Lake. This data is used to power telemetry apps, which are cloud-based applications that make it easy to monitor and manage your next-generation firewalls and Panoramas." This is an eyebrow raising feature, and one I hope that I would have had the foresight to disable.
- deleted 2y ago[deleted]
- ymyms 2y agoDisable? This is the type of thing that enterprises make the conscious effort to pay for a higher tier license and enable.
- FreakLegion 2y agoThere's nothing eyebrow-raising about the feature itself. It's off by default, lets you control which kinds of data you share if you choose to share data at all, and is mainly used for basic operations (e.g. tracking CPU load, concurrent sessions, and other relevant metrics over time).
- spudlyo 2y agoI'm not entirely comfortable with a security device streaming telemetry to a third party. The kind of metrics that you're thinking of have historically been made available on management interfaces via SNMP OIDs assigned to the manufacturer. Personally I'd much prefer to poll the device myself and keep those metrics in-house. This may seem like an antiquated way of managing network devices, but SNMP is a well understood, interoperable, standards-based protocol without vendor lock-in. Futhermore, as we've seen, features like these expose a larger attack surface on the device. My primary worry would have been around it being used somehow in a data exfiltration scheme, but a root-level compromise of the device is the worst possible outcome.
- FreakLegion 2y ago
- paleotrope 2y agoWow, 2 days for a fix, over a weekend.
- FuriouslyAdrift 2y agoFirmware patch should be available on the 14th
- justusthane 2y agoTwo days for a hotfix, but by the time we saw the notice of this CVE, PaloAlto had already pushed a content update that automatically blocks this vulnerability (provided you have the vulnerability profile applied correctly).
- _8j50 2y agoI've been trying to get a copy of panos for fuzzing/research myself but unless I set up a reputable llc that seems impossible. They've ignored every request for purchase I've made. If anyone has tips on how to get started with this do let me know. It seems not allowing researchers even black-box access is their strategy to secure the platform.
- FreakLegion 2y agoIf you're trying to buy from them directly you aren't going to get anywhere. Palo Alto is a channel company; you need to find a channel partner that considers a one-off sale worth their time. Palo Alto does do direct deals, but not small ones. There's an easier way to get a firewall spun up, though. https://aws.amazon.com/marketplace/pp/prodview-nkug66dl4df4i https://aws.amazon.com/marketplace/pp/prodview-nkug66dl4df4i looks like the current version. I'm still running https://aws.amazon.com/marketplace/pp/prodview-3xtziatyes54i https://aws.amazon.com/marketplace/pp/prodview-3xtziatyes54i and can't speak to the newer option directly, but there should be something suitable on all of the big cloud providers.
- _8j50 2y agoThanks, I think the cloud approach is the only way, I wanted to do it locally. For personal use, cloud providers are very hostile, especially if your use case is to do things that aren't normally done.
- neilv 2y agoI've bought a Palo Alto Networks big blue box on eBay in the past. If you're only using it for legitimate research, the licensing subtleties seem different than if you were using it for the benefit of its product features. For people working in enterprise IT, word was (a least a few years ago) your salesperson could hook you up to purchase one their small boxes with a license, for home use. It's in their interest to have IT people familiar with their products. But (unlike whatever you bought on eBay) I don't know whether that license would have you agreeing to restrictions on research investigation, or to restrictions on talking about the product.
- 2y ago
- userbinator 2y agoWhat does HN consider to be a good alternative VPN to GlobalProtect?
- xpltr 2y agoA MITM TLS firewall product by Palo Alto Networks who hire employees for Unit 42 based in Israel who are definitely overseen by IDF, Mossad, NSA. There is a backdoor in every one of their products. And sending "telemetry" data to PAN is just a "security" ruse to further digitally fingerprint the end users. With so much i/o data and overwhelmed dev teams, these CEOs/CSOs trust & surrender the keys to their company to intelligence agencies by proxy. Then when these intelligence agencies want to sink the stock of these companies they flip the switch with a ransomware or other zero day, which they'll blame on china, to keep the cyber attack fear alive, prospering whatever other companies they have in mind. Plus gathering immense amounts of data on all operational aspects of that company, which then can be sent to investment group BlackRock's super computer "Aladdin" for further manipulation and control. Think about it, a MITM TLS appliance, own by a 3rd party, sitting in the middle of a conglomerate company's network. Real stupid.