Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

At a certain point, it just becomes oppressive.

Darknet Diaries
174: Pacific Rim

Like, the amount of patching that you have to do and the analysis involved in that and, you know, fixing the firewall takes just as much QA.

Darknet Diaries
174: Pacific Rim

You know, it takes time to build things that don't break.

Darknet Diaries
174: Pacific Rim

And these are critical – I don't want to say they're critical infrastructure, but they're protecting critical infrastructure –

Darknet Diaries
174: Pacific Rim

Yeah, over time, the threat actors were increasingly, they were targeting specific organizations or specific groups.

Darknet Diaries
174: Pacific Rim

They had identified who all of the customers were.

Darknet Diaries
174: Pacific Rim

in those early attacks because they smacked all of the firewalls at once and grabbed some data.

Darknet Diaries
174: Pacific Rim

Well, it turns out that the CyberRome code is the predecessor to the XG Firewall code.

Darknet Diaries
174: Pacific Rim

So CyberRome was the company that Sophos bought, and their product became the XG Firewall.

Darknet Diaries
174: Pacific Rim

So back in 2018, we're talking about how

Darknet Diaries
174: Pacific Rim

the threat actors had stolen the source code, you know, they were using some of that still to find additional vulnerabilities.

Darknet Diaries
174: Pacific Rim

And they found a vulnerability.

Darknet Diaries
174: Pacific Rim

At this point, CyberRome and the XG firewall were in parallel operating, but CyberRome was about to be phased out.

Darknet Diaries
174: Pacific Rim

It was about to be end of life.

Darknet Diaries
174: Pacific Rim

And the threat actors found a vulnerability that allowed them to create an admin-level account on the box with just a SQL injection query that was pre-authentication.

Darknet Diaries
174: Pacific Rim

So they could just hit the SQL server that was running on the firewall from the outside and run a command that was able to get it to add a user with admin access.

Darknet Diaries
174: Pacific Rim

And then they could log in on any cyber room firewall that they wanted to with that credential.

Darknet Diaries
174: Pacific Rim

And there was no easy fix for it.

Darknet Diaries
174: Pacific Rim

And because the product was close to end of life, Sophos just decided to rush it to end of life and get everybody who was running a Cyber Roam firewall to upgrade to the latest XG.

Darknet Diaries
174: Pacific Rim

put that one to bed because it was, it was the point where if we had to start, you know, tracking attack against CyberRome and XG Firewalls, that would have taken the entire, like all of the entire team's resources all the time.