Live data from Hacker News

Palo Alto Networks PAN-OS Zero-Day Exploitation

volexity.com

41–50 of 66 posts

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#41
post #26

I've been trying to get a copy of panos for fuzzing/research myself but unless I set up a reputable llc that seems impossible. They've ignored every request for purchase I've made. If anyone has tips on how to get started with this do let me know. It seems not allowing researchers even black-box access is their strategy to secure the platform.

Just buy a lab unit from CDW. The American website annoyingly has a "call us" for pricing but a PA-440 is $979 CAD for comparison.

https://www.cdw.ca/product/palo-pa-440-security-appliance-la...

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#42
post #32

Earlier quoted context omitted.

The premise is that a business needs to know what kind of data is passing through its networks. SSL forward proxy (man in the middle) helps this by letting the firewall see contents of data, more thoroughly govern access to websites and subcomponents of websites, and so on. For example, with MITM enabled, a Palo firewall can grant access to the viewing of Youtube videos, but not the upload or commenting of them. It c…

Honest question: have you ever seen a corporate TLS middleware box stop an active threat? And I don’t mean drive-by crap like port scanning for sshd…

Its typically used for detecting malware, detecting data loss prevention, or forensics. "Drive by crap like port scanning for sshd" isn't even relevant to why companies mitm SSL. And yes I see it detect but not stop active threats on a daily basis.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#43
post #10

I understand that these products has market demands from paranoid but not IP networking related businesses, but I never quite understood the fundamental basic premise of Palo Alto, F5 Networks, Fortinet, etc. brands of "MITM TLS firewall" products. These firewall boxes are on-prem white hat Mallory, reverse-reverse-proxying all TLS traffic. And of course the Linux stack it uses has tons of RCEs and misconfigurations.…

As someone that I have worked for years with this kind of products in a couple of F500, I hate them with all of my heart. I really prefer the approach based on DNS and IP filtering, it's easier to manage and doesn't have all the problems that SSL inspection has.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#44
post #27
post #11

Earlier quoted context omitted.

In case of Palo Alto Networks TLS interception wasn't the only, or even main, use in many places. Among reasons one might have seen them was centralised control plane, multipoint VPNs, yes deep-packet inspection (including for simply checking if the expected protocol was running on given traffic), they could be also simply used as pretty advanced router+firewall setup.

If you have a TLS MITM proxy configured and an attacker pwns the proxy, it’s pretty much game over. Forget access to the internal network: any host that has the MITM proxy’s certificate installed will trust it to view and modify all TLS traffic . This gets a free attack on all web origins without even compromising anything else. AWS console, check. Configuration of other corporate appliances, check. Everyone’s commun…

I'm not saying no.

I'm just saying that not everyone used PAN NGFW for MITM proxying, and it's not necessary to enable/configure that to use them for other tasks.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#45
post #2

> Q. Has my device been compromised by this vulnerability? > Customers are able to open a case in the Customer Support Portal (CSP) and upload a technical support file (TSF) to determine if their device logs match known indicators of compromise (IoC) for this vulnerability. They can't be serious...

You want them to share their IoC so the exploit authors can add to the exploit’s mitigations?

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#46
A MITM TLS firewall product by Palo Alto Networks who hire employees for Unit 42 based in Israel who are definitely overseen by IDF, Mossad, NSA. There is a backdoor in every one of their products. And sending "telemetry" data to PAN is just a "security" ruse to further digitally fingerprint the end users. With so much i/o data and overwhelmed dev teams, these CEOs/CSOs trust & surrender the keys to their company to intelligence agencies by proxy. Then when these intelligence agencies want to sink the stock of these companies they flip the switch with a ransomware or other zero day, which they'll blame on china, to keep the cyber attack fear alive, prospering whatever other companies they have in mind. Plus gathering immense amounts of data on all operational aspects of that company, which then can be sent to investment group BlackRock's super computer "Aladdin" for further manipulation and control. Think about it, a MITM TLS appliance, own by a 3rd party, sitting in the middle of a conglomerate company's network. Real stupid.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#47
post #10

I understand that these products has market demands from paranoid but not IP networking related businesses, but I never quite understood the fundamental basic premise of Palo Alto, F5 Networks, Fortinet, etc. brands of "MITM TLS firewall" products. These firewall boxes are on-prem white hat Mallory, reverse-reverse-proxying all TLS traffic. And of course the Linux stack it uses has tons of RCEs and misconfigurations.…

> Isn't that just insecure???

You seem to be singularly focused on the software quality of the VPN. It’s important, but is far from the only aspect of security.

The company is worried both about keeping the bad guys out of their network and keeping their IP + secrets inside. The motivation for the TLS MITM blinks boxes is for the latter.

It’s easy as an employee to simply discount the value of decrypting your internet traffic, but the truth is that the company has a responsibility to protect against malicious insiders, malware/ransomware exfiltration, etc.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#48
post #32

Earlier quoted context omitted.

The premise is that a business needs to know what kind of data is passing through its networks. SSL forward proxy (man in the middle) helps this by letting the firewall see contents of data, more thoroughly govern access to websites and subcomponents of websites, and so on. For example, with MITM enabled, a Palo firewall can grant access to the viewing of Youtube videos, but not the upload or commenting of them. It c…

Honest question: have you ever seen a corporate TLS middleware box stop an active threat? And I don’t mean drive-by crap like port scanning for sshd…

These are more of an analyst tool for detection than blocking.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#49
post #28

Earlier quoted context omitted.

One company had a related (but less defensible) decision, coming down from the top, which broke CI runners and other things, and the poor overworked Git&CI infra lead was trying to work around it. They asked me to be a Git reviewer for their big workaround, and I found around a dozen new vulnerabilities and future build-breaking defects that the workaround introduced. I also told them that it's unreasonable for this…

The root causes are usually among: Security teams are often staffed by people who have no operational experience, and do not understand the consequences of what they are recommending or even mandating. Often those staff are blindly following hardening guides or asking for every configuration switch to be flipped to "most secure" setting without having a good understanding of the threat model for the workload and with…

You nailed it. In my experience these "security" teams accumulate people who want PM level powers without having to deal with any of the accountability.

The fact is that security is a holistic concept and can ONLY be evaluated in context. That in turn requires good technical and operational knowledge. But people like that are rare and expensive, so instead we have entire armies of box-tickers who lack the intellectual capacity to even understand what a "tradeoff" means.

Something went terribly wrong around the mid-90s, when security changed from a discipline practised and understood by hands-on professionals into a consulting gig.

Disclosure: I've been doing infosec professionally since 1993.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#50
post #10

I understand that these products has market demands from paranoid but not IP networking related businesses, but I never quite understood the fundamental basic premise of Palo Alto, F5 Networks, Fortinet, etc. brands of "MITM TLS firewall" products. These firewall boxes are on-prem white hat Mallory, reverse-reverse-proxying all TLS traffic. And of course the Linux stack it uses has tons of RCEs and misconfigurations.…

> Isn't that just insecure??? You seem to be singularly focused on the software quality of the VPN. It’s important, but is far from the only aspect of security. The company is worried both about keeping the bad guys out of their network and keeping their IP + secrets inside. The motivation for the TLS MITM blinks boxes is for the latter. It’s easy as an employee to simply discount the value of decrypting your interne…

> but the truth is that the company has a responsibility to ...

These boxes provide a one-stop hacker shop for all data exfil and malware injection that normally don't exist. In theory they can _sign security updates_, send fake announcements, just intercept, redirect and drop emails, etc. It's just too hard for me to understand how it's supposed to add security, unless these would be NSA endorsed or something.

Post reply on HN