Fixing critical vulnerabilities in Apache's remote desktop
blog.checkpoint.com
Fixing critical vulnerabilities in Apache's remote desktop
1–9 of 9 posts
Re: Fixing critical vulnerabilities in Apache's remote desktop
#2Re: Fixing critical vulnerabilities in Apache's remote desktop
#3Re: Fixing critical vulnerabilities in Apache's remote desktop
#4I applaud them for using open source software, and contributing back their findings, but my first thought reading this was "isn't it a little odd a security appliance vendor who actively markets a "Remote Secure Access" system doesn't rely on there own systems?" Their website has a whitepaper link on every page on how your business should use them for remote access.
I suspect you are right that it's just a story telling prop, but they did address why it might be practical for them to have such a solution in place.
Re: Fixing critical vulnerabilities in Apache's remote desktop
#5Here is the link to the full technical paper: https://research.checkpoint.com/2020/apache-guacamole-rce/
Re: Fixing critical vulnerabilities in Apache's remote desktop
#6Re: Fixing critical vulnerabilities in Apache's remote desktop
#7I wonder how many other 5000+ employee companies that develop their own remote access software have an entire separate redundant system..
How many 5000+ employee companies do have redundant system? How may have only a single highly proprietary system without any fallback?
Re: Fixing critical vulnerabilities in Apache's remote desktop
#8I wonder how many other 5000+ employee companies that develop their own remote access software have an entire separate redundant system..
You can cut off your own arms pretty easily even if you're not the vendor, but it would look particularly bad for them.
Yeah in theory disciplined updates and testing should resolve the risk, but sensible to have a fallback.