Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
944 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

And this was a really bad bug for Sophos to discover.

Darknet Diaries
174: Pacific Rim

Their devices are supposed to be blocking hackers from getting into the network, yet it's the vulnerable device which is allowing hackers into it?

Darknet Diaries
174: Pacific Rim

These firewalls weren't just vulnerable.

Darknet Diaries
174: Pacific Rim

They all had been hacked into, exploited.

Darknet Diaries
174: Pacific Rim

Someone probably scanned the whole internet looking for these particular Sophos firewalls and then ran some kind of automation script to go infect them all.

Darknet Diaries
174: Pacific Rim

Hot dog, 80,000 Sophos firewalls hacked into.

Darknet Diaries
174: Pacific Rim

But just because someone put a URL in place where it shouldn't be, that's not all that damaging just by itself.

Darknet Diaries
174: Pacific Rim

So the team investigated what that URL did, and that's when they started to panic.

Darknet Diaries
174: Pacific Rim

The URL would trigger a git request in order to update the Sophos firewall itself.

Darknet Diaries
174: Pacific Rim

But what was really weird about it is that

Darknet Diaries
174: Pacific Rim

And Sophos didn't own that domain.

Darknet Diaries
174: Pacific Rim

So it tried to blend in like it was supposed to be there.

Darknet Diaries
174: Pacific Rim

And it fooled many of the people even at Sophos who just figured the update domains changed.

Darknet Diaries
174: Pacific Rim

But my goodness, this meant suddenly 80,000 firewalls were looking somewhere else for updates and not to Sophos?

Darknet Diaries
174: Pacific Rim

And I don't know if you fully understand what this means.

Darknet Diaries
174: Pacific Rim

If a malicious actor is able to send your firewall software updates, then they can put in whatever they want.

Darknet Diaries
174: Pacific Rim

They can give themselves full access to the firewall, or they can log all traffic going through it.

Darknet Diaries
174: Pacific Rim

They can poke a hole in the firewall and let themselves right into your network.

Darknet Diaries
174: Pacific Rim

And then from there, they can just infect your whole network with ransomware.

Darknet Diaries
174: Pacific Rim

The thing that is supposed to block unwanted traffic is no longer blocking anything if the attacker wants it that way.