Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

that they are specifically interested in taking a closer look at.

Darknet Diaries
174: Pacific Rim

So these machines that they believe are being operated by threat actors, where they're doing these commands that are way outside of the boundaries of normal firewall behavior.

Darknet Diaries
174: Pacific Rim

And these things are capable of doing more than just sending log entries.

Darknet Diaries
174: Pacific Rim

They're able to pick arbitrary fields from the file system on the firewall and send those files back.

Darknet Diaries
174: Pacific Rim

So that was how, in some cases, the team started throwing these kernel implants onto some of these firewalls that we could see were being used to do this experimentation.

Darknet Diaries
174: Pacific Rim

And they were retrieving all sorts of very malicious and pretty dangerous files that were being dropped on these machines by the people who were developing these exploits and were testing them out in advance of attacks.

Darknet Diaries
174: Pacific Rim

Wow, that is wild.

Darknet Diaries
174: Pacific Rim

Is that going too far?

Darknet Diaries
174: Pacific Rim

To call it malware is kind of a misnomer.

Darknet Diaries
174: Pacific Rim

I mean, I'm not going to defend the overall argument here, but I will just say that there is nothing malicious about wanting to know what someone who is doing malicious things with your product is doing.

Darknet Diaries
174: Pacific Rim

You know, it's kind of an ethical gray area.

Darknet Diaries
174: Pacific Rim

Now, just being the, you know, person who's telling this story of what happened, uh,

Darknet Diaries
174: Pacific Rim

We were observing in the world, not just Sophos firewalls, but every firewall vendor getting hit with zero days.

Darknet Diaries
174: Pacific Rim

Their customers being attacked in various ways.

Darknet Diaries
174: Pacific Rim

And there being no way to resolve this.

Darknet Diaries
174: Pacific Rim

And certainly no way to anticipate it.

Darknet Diaries
174: Pacific Rim

Now, whether or not other companies are doing the same thing,

Darknet Diaries
174: Pacific Rim

No one else has disclosed that, but I don't think it's outside the realm of possibility to think that maybe some of them were.

Darknet Diaries
174: Pacific Rim

Yeah, well, there was SophosFirewallUpdate.com and SophosProductUpdate.com which were registered at different registrars and hosted in different IP spaces.

Darknet Diaries
174: Pacific Rim

But because they both had Sophos in the name and they were part of this attack, Sophos went to ICANN and did the domain name seizure process on those domains.