Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
944 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

So flash forward two years go by.

Darknet Diaries
174: Pacific Rim

It sounds like a minor problem at the surface.

Darknet Diaries
174: Pacific Rim

This firewall had a configuration which showed what IPs are allowed to access it and manage it and configure it.

Darknet Diaries
174: Pacific Rim

And a strange URL was showing up in that list of IPs.

Darknet Diaries
174: Pacific Rim

It didn't make any sense as to why it was there or why anyone would ever even put it there.

Darknet Diaries
174: Pacific Rim

At the same time, someone outside of Sophos submitted a bug into Sophos for this same issue.

Darknet Diaries
174: Pacific Rim

Someone from China with a trial license of the Sophos firewall found this bug and reported it to Sophos?

Darknet Diaries
174: Pacific Rim

And Sophos did, in fact, pay the bug bounty for this.

Darknet Diaries
174: Pacific Rim

Someone got paid a pretty penny for reporting this bug to Sophos at almost the exact same time that they were seeing it being exploited by devices in the wild.

Darknet Diaries
174: Pacific Rim

We called it Asna Rock.

Darknet Diaries
174: Pacific Rim

So the team investigated this bug further.

Darknet Diaries
174: Pacific Rim

It was present in the front-end web user interface of the firewall.

Darknet Diaries
174: Pacific Rim

To configure this firewall, you can use a browser and access it that way.

Darknet Diaries
174: Pacific Rim

Well, the web UI of this firewall had an SQL injection vulnerability in it.

Darknet Diaries
174: Pacific Rim

Basically, in one of the form fields of the firewall, like maybe the username field or something, an attacker could enter in some commands there, which would glitch out the user input handling mechanism of the firewall and allow the attacker to inject their own commands there

Darknet Diaries
174: Pacific Rim

into the database of the firewall where the configuration sat.