Live data from Hacker News

The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

blogs.cisco.com

31–36 of 36 posts

Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

#31
post #8

re: EXTRABACON If you have SNMP listening on a public ipv4/ipv6 interface of a firewall (I don't care if it's an EOL/EOS PIX or not), you have done something fundamentally wrong from the start. As a network engineer seeing something like this in a business customer's equipment would cause me to seriously reconsider all other decisions/security configurations made by a predecessor or third party contractor.

If you have a sufficiently large network, for a sufficiently long time, someone, somewhere, will fuck up an ACL.

This isn't an ACL setting. You have to specifically ask an ASA to bind SNMP to the external interface.

Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

#32
post #8

re: EXTRABACON If you have SNMP listening on a public ipv4/ipv6 interface of a firewall (I don't care if it's an EOL/EOS PIX or not), you have done something fundamentally wrong from the start. As a network engineer seeing something like this in a business customer's equipment would cause me to seriously reconsider all other decisions/security configurations made by a predecessor or third party contractor.

The point of EXTRABACON isn't to break into networks protected by an ASA; it's to persist onto that network by infecting the firewall after you manage somehow to bypass it. It's of a kind with exploits for other firewalls through management interfaces that can't be reached on the public interface.

Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

#33

Is this a standard naming convention for exploits?

Those are the names of compartments / projects for classified information.

The way compartments work, they are supposed to be isolated not just from lower level (secret vs top secret) but also among each other. So things would have instructions like "handle via EPICBANANA channels only". So if you are not read into EPICBANANA you don't get access to it, even though you might have TS clearance.

So programs / capabilities are referred by those names. Instead of say "Oh that Cisco ASA blah model VPN MitM thing we have".

That also means that just because you have TS clearance doesn't mean you get to pick up and walk away with all the TS information you want ... oh wait, that did happen already, didn't it... oops.

Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

#34
post #8

re: EXTRABACON If you have SNMP listening on a public ipv4/ipv6 interface of a firewall (I don't care if it's an EOL/EOS PIX or not), you have done something fundamentally wrong from the start. As a network engineer seeing something like this in a business customer's equipment would cause me to seriously reconsider all other decisions/security configurations made by a predecessor or third party contractor.

I agree but if there is one lesson I've learned, its that often when you find such environments it is due to failure of the management/execs to properly support the IT team, so they cut corners, halfass it, or hire contractors as you mentioned. True it shouldnt be done, but if you are selling equipment to a business who has had this failing, its just something to be aware of. Im so damn tired of companies underfundin…

No way. That's straight up incompetence.

Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

#35
post #33

Is this a standard naming convention for exploits?

Those are the names of compartments / projects for classified information. The way compartments work, they are supposed to be isolated not just from lower level (secret vs top secret) but also among each other. So things would have instructions like "handle via EPICBANANA channels only". So if you are not read into EPICBANANA you don't get access to it, even though you might have TS clearance. So programs / capabilit…

Snowden was a member of a group with what is known as "PRIVAC", or privileged access, capabilities. To my amateur understanding, this type of access is granted to systems administrators or other users of information systems who may see things they aren't otherwise cleared to see in the course of their normal duties. Additionally, it was reported, though denied by Snowden, that Snowden used other colleagues' credentials to access information for collection and later disclosure.

Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits

#36
post #32
post #8

re: EXTRABACON If you have SNMP listening on a public ipv4/ipv6 interface of a firewall (I don't care if it's an EOL/EOS PIX or not), you have done something fundamentally wrong from the start. As a network engineer seeing something like this in a business customer's equipment would cause me to seriously reconsider all other decisions/security configurations made by a predecessor or third party contractor.

The point of EXTRABACON isn't to break into networks protected by an ASA; it's to persist onto that network by infecting the firewall after you manage somehow to bypass it. It's of a kind with exploits for other firewalls through management interfaces that can't be reached on the public interface.

Still, I wonder how long before we see it weaponized by adding this as a payload to ordinary desktop malware. A nice trick would be something that scans the local network, infects the ASA (people are pretty good about keeping SNMP off the internet, possibly less good about keeping it off the internal interfaces), and then does HTTP injection from the ASA with SecondDate of either a malicious or advertising payload.
Post reply on HN