The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
blogs.cisco.com
The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
1–10 of 36 posts
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#2Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#3"JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks. The purpose of digitally signed Cisco software is to increase the security posture of Cisco ASA devices by ensuring that the software running on the system has not been tampered with and originated from a trusted source as claimed."
They claim that the implant is digitally signed, then they say that it shouldn't work because Cisco software is digitally signed also, and it's verified by the Cisco Secure Boot.
Isn't that a bit contradictory? sure they might have had flaws in their verification process (we've seen signature verifications that were nothing more than "is this a signed message" before) but since Cisco verifies the signature properly (as you haven't been able to binary patch Cisco boot images for 5+ years) doesn't this implies that the NSA got a hold of the signing keys used by Cisco or an authorized 3rd party?
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#4On thing I find odd is "JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks. The purpose of digitally signed Cisco software is to increase the security posture of Cisco ASA devices by ensuring that the software running on the system has not been tampered with and originated from…
It suggests to me that the previous signature style was a symmetric type, whereas now it's asymmetric.
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#5On thing I find odd is "JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks. The purpose of digitally signed Cisco software is to increase the security posture of Cisco ASA devices by ensuring that the software running on the system has not been tampered with and originated from…
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#6On thing I find odd is "JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks. The purpose of digitally signed Cisco software is to increase the security posture of Cisco ASA devices by ensuring that the software running on the system has not been tampered with and originated from…
Where do they claim that? Both occurrences of the words "digitally signed" in the quoted section refer to the new Cisco software and not to the JETPLOW payload.
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#7Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#8If you have SNMP listening on a public ipv4/ipv6 interface of a firewall (I don't care if it's an EOL/EOS PIX or not), you have done something fundamentally wrong from the start. As a network engineer seeing something like this in a business customer's equipment would cause me to seriously reconsider all other decisions/security configurations made by a predecessor or third party contractor.
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#9On thing I find odd is "JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks. The purpose of digitally signed Cisco software is to increase the security posture of Cisco ASA devices by ensuring that the software running on the system has not been tampered with and originated from…
The advisory is saying that JETPLOW is not signed. And thus, in newer platforms where signing is implemented, it would prevent that type of attack.
Re: The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
#10On thing I find odd is "JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks. The purpose of digitally signed Cisco software is to increase the security posture of Cisco ASA devices by ensuring that the software running on the system has not been tampered with and originated from…