Live data from Hacker News

Palo Alto Networks PAN-OS Zero-Day Exploitation

volexity.com

1–10 of 66 posts

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#2
> Q. Has my device been compromised by this vulnerability?

> Customers are able to open a case in the Customer Support Portal (CSP) and upload a technical support file (TSF) to determine if their device logs match known indicators of compromise (IoC) for this vulnerability.

They can't be serious...

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#6
You can sort their announcements by CVSS here:

https://security.paloaltonetworks.com/?sort=-cvss

This is their 3rd CVSS 10 in the past 5 years and they've had quite a few more over 9s in the past 5-10 years. I have no idea how that compares to other places like them, maybe they're all like this?

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#7
post #3

I'll stick to using a Linux firewall.

PaloAlto devices ARE “Linux Firewalls” https://live.paloaltonetworks.com/t5/general-topics/how-to-a...

They probably mean some Linux distro with no crapware on top. Seeing how this exploit seems to be PaltoAlto-specific stuff built on top of the basic OS, GP's approach sounds sensible enough.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#8
post #3

I'll stick to using a Linux firewall.

PaloAlto devices ARE “Linux Firewalls” https://live.paloaltonetworks.com/t5/general-topics/how-to-a...

They aren't exactly linux firewalls, even if they run linux as management OS.

AFAIK the forwarding engine is custom(ized), and on physical devices some of them offload to FPGA - or at least they used to when I administrated some 2014~2016.

The management UI was in PHP :P

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#9
Global Protect is up there with Citrix Netscaler and Fortigate SSLVPN in the list of "secure" remote access products that no organization should be using without considering the fact that another easy RCE is going to come out roughly every 12 months and possibly lead to a ransomware incident.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#10
I understand that these products has market demands from paranoid but not IP networking related businesses, but I never quite understood the fundamental basic premise of Palo Alto, F5 Networks, Fortinet, etc. brands of "MITM TLS firewall" products.

These firewall boxes are on-prem white hat Mallory, reverse-reverse-proxying all TLS traffic. And of course the Linux stack it uses has tons of RCEs and misconfigurations.

Isn't that just insecure???

Post reply on HN