Zero Day Bug Found in Popular Firewalls

Поділитися
Вставка
  • Опубліковано 14 кві 2024
  • In this video I discuss the critical command injection vulnerability in PAN-OS (used on Palo Alto Networks firewalls) that is being actively exploited and how how can secure yourself against this threat.
    My merch is available at
    based.win/
    Subscribe to me on Odysee.com
    odysee.com/@AlphaNerd:8
    ₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
    Monero
    45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
    Bitcoin
    3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
    Ethereum
    0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
    Litecoin
    MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
  • Наука та технологія

КОМЕНТАРІ • 234

  • @EmM-ko7mu
    @EmM-ko7mu 23 дні тому +712

    whats with all the vulnerabilities being found this month

    • @symbioticparasite6268
      @symbioticparasite6268 23 дні тому +20

      Jacky be hacky

    • @archimedesbird3439
      @archimedesbird3439 23 дні тому

      @@johnsmith8981
      Stop deifying AI, it's a tech bubble fed by illegally scraped data and nothing more.

    • @vigilantmug5028
      @vigilantmug5028 23 дні тому

      Better than feds and other "cyber security specialists" exploiting them as zero days under the radar

    • @dogyX3
      @dogyX3 23 дні тому +264

      The XZ exploit sparked everyone to check their defences again.

    • @MaxiTimmi
      @MaxiTimmi 23 дні тому +14

      @@johnsmith8981 I am sure cyber security companies would be able to use AI as well for their systems so it's unlikely that would happen

  • @jonahkrompart
    @jonahkrompart 23 дні тому +239

    It’s hilarious that this takes place over the device telemetry channel, AKA the spyware that Palo Alto highly encourages you to not opt out of

    • @JacobyB
      @JacobyB 23 дні тому +9

      because it collects errors 🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯

    • @LailSidgar
      @LailSidgar 22 дні тому +8

      @@JacobyB It collects errors. Good thing bugs are features and not errors.

    • @ARCNSPUDS
      @ARCNSPUDS 22 дні тому +1

      It doesn’t matter if telemetry is on or not

    • @jonahkrompart
      @jonahkrompart 21 день тому +2

      @@ARCNSPUDS Palo specifically recommended in their advisory that you disable telemetry to mitigate the issue, I’m sure you know better than them

    • @kilosandkeyboards
      @kilosandkeyboards 21 день тому

      @@jonahkrompart Nah, there was an update from PANW which states that telemetry does not need to be enabled for this CVE to be exploited.

  • @UnlimitedPepsi
    @UnlimitedPepsi 23 дні тому +291

    State sponsored threat actors seething hard rn.

  • @Jango1989
    @Jango1989 22 дні тому +9

    That feeling when the firewall glows brighter than the fire...

  • @user-in2cs1vp6o
    @user-in2cs1vp6o 23 дні тому +237

    Don't worry, my firewall has a firewall.

    • @Exigentable
      @Exigentable 23 дні тому +41

      good luck pal i'm 7 firewalls deep

    • @marconiandcheese7258
      @marconiandcheese7258 23 дні тому +8

      Yo dawg I heard you liked firewalls so I got your firewall a firewall

    • @necktwister666
      @necktwister666 23 дні тому +7

      firewall²

    • @nitproject5193
      @nitproject5193 23 дні тому +1

      it doesn't matter if they are on a same network and one of them can be compromized

    • @elpsykongr00
      @elpsykongr00 22 дні тому +2

      Firecube

  • @zaremol2779
    @zaremol2779 23 дні тому +90

    This isn't a 0-day, this is an alphabet soup agency backdoor

  • @hvher
    @hvher 23 дні тому +131

    Month of vulnurabs

    • @Alfred-Neuman
      @Alfred-Neuman 23 дні тому +5

      Yeah wtf is happening?

    • @juho1882
      @juho1882 20 днів тому

      ​@@Alfred-Neumanthese are found all the time. people have just been making more videos of them lately

  • @jonahhekmatyar
    @jonahhekmatyar 23 дні тому +75

    NSA must be seething this month

  • @Daniel-sj2mu
    @Daniel-sj2mu 23 дні тому +49

    It was over for Palo Alto once Professor Messer stopped working there

    • @fiverZ
      @fiverZ 22 дні тому +1

      Context?

  • @sampatton146
    @sampatton146 23 дні тому +29

    Back door insisted by the glowies

  • @deef0
    @deef0 23 дні тому +19

    I work in cybersec, got this one on my desk under NDA very late march. Patch was out when they announced it to the rest

  • @hakawatis
    @hakawatis 23 дні тому +121

    in 2016 we were only discovering maybe 10K-30K CVE's a year.
    in 2022 we were discovering 100,000 CVEs a year.
    in 2024 we're discovering 4x the amount of CVEs a year.
    goodluck blue team. this year is gonna be hell for you. 😭😭

    • @rohanofelvenpower5566
      @rohanofelvenpower5566 23 дні тому +7

      get out of infosec, its an overworked industry and it will only get worse. bad career choice. like videogaming industry.

    • @syedibrahimkhalil2708
      @syedibrahimkhalil2708 23 дні тому +23

      @@rohanofelvenpower5566 lol with that mindset, I wonder what insecure world would we live in then. This actually give a survival bias, where in actual there is 'more' need of infosec than running out of it.

    • @markmonster3315
      @markmonster3315 23 дні тому +9

      @@rohanofelvenpower5566 Isn't that exactly the reason to get into it?

    • @rj7250a
      @rj7250a 23 дні тому +14

      ​@@markmonster3315if you enjoy regular overtime, 10 hours shifts, sometimes and earning 5x less than some dude typing SQL commands at a bank for 10 hours a week, sure.
      That is basically game dev industry, that is why i always say to new programmers to not do game dev.
      I do not know about cybersec industry, maybe it is not as bad, since it is more boring than game dev.
      The pay and working conditions of a programming job is proportional to how boring it is.
      - me, 2024

    • @lokeshchandak3660
      @lokeshchandak3660 23 дні тому +2

      ​@@rj7250aso the more boring something is, the better the pay and the better the work conditions?
      I have a feeling you meant to say inversely proportional...

  • @jer1776
    @jer1776 23 дні тому +17

    TLDR: Your firewall should have a firewall

  • @adrianfisher3349
    @adrianfisher3349 23 дні тому +24

    I wanted an enterprise grade firewall for my home network so I could gain work experience with it. I couldn't afford any of them I saw and then loads of flaws in them were announced. I then bought a workstation/server and installed OpenBSD on it and love it.

    • @adrianfisher3349
      @adrianfisher3349 23 дні тому +1

      @GhOs7-Operator WiFi isn't very good under OBSD but I used an old Asus router for that, which is connected to my firewall though and Ethernet cable and I have no problems there either. I put 16GB ECC RAM in (this was 2015) which I know is much more than would be needed but it let me setup part of it as a RAM disk so the SSD drive is almost only used during boot ups and software updates to help it last longer.

  • @ruthlessadmin
    @ruthlessadmin 23 дні тому +15

    I'm responsible for a pair of Fortigate appliances. We've had to patch out vulnerabilities before but we generally stay on top of it. While we are attacked relentlessly and constantly, we've so far never had a breech (at least not that we know of yet). What's frustrating, is I can't get upper management to take anything seriously, so we have a weak backup policy and no budget to do anything.

    • @spacemeter3001
      @spacemeter3001 23 дні тому +5

      They'll learn once they get compromised

    • @chimagamer4157
      @chimagamer4157 23 дні тому +2

      Maybe sell it to them like an insurance policy, you rather pay some money in order not to become bankrupt, incase it does go bad
      Because this would be the worst possible outcome.

    • @dracula7779
      @dracula7779 22 дні тому

      @@spacemeter3001 hopefully, but some still don't

    • @Silentguy_
      @Silentguy_ 21 день тому

      I manage one at work and a personal one at home.
      We’ve closed off as much as we can and enabled 2FA on basically everything but with how bad exploits have gotten over the past few years, I take a zero tolerance policy towards updating.
      If a new update drops, I send out a email saying internet will be offline for about 5 minutes at the end of the day and the only one that can tell me any different is my boss’s boss.

  • @imjonkatz
    @imjonkatz 23 дні тому +59

    When you wonder if it's a bug or a feature...

  • @chubbycatfish4573
    @chubbycatfish4573 23 дні тому +46

    It's always something, isn't it?

    • @_ruddegar
      @_ruddegar 23 дні тому +6

      Keeps me employed!

    • @dinguscollective1872
      @dinguscollective1872 21 день тому +1

      @@_ruddegar pretty much why this shit is happening lmao. more jobs I guess

    • @_ruddegar
      @_ruddegar 20 днів тому

      @dinguscollective1872 lol you might be on to something.

  • @deadshxll
    @deadshxll 23 дні тому +4

    funnily enough, the Security+ certificate which is considered fundamental cert, provided by CompTIA, actually calls out that security controls themselves have the possibility to be vulnerable and open to attack vectors.

  • @lukeskywalker2116
    @lukeskywalker2116 22 дні тому

    Nice walkthrough. Thank you.

  • @denerlkonig277
    @denerlkonig277 23 дні тому +1

    Thank you for the video

  • @caine_inu
    @caine_inu 23 дні тому

    It's funny how I was looking at this in the morning & now you published a video about it.

  • @13thravenpurple94
    @13thravenpurple94 23 дні тому

    Excellent video 👍 Thank you 💜

  • @BJ-sq1si
    @BJ-sq1si 23 дні тому +1

    Your security vulnerability discovery videos are my favorite

  • @dmitrypandov8279
    @dmitrypandov8279 23 дні тому +1

    oh that swag "Won't fix" still gives me chuckle

  • @evccyr
    @evccyr 23 дні тому +8

    Vulnerabilities playing April fools the entire month

  • @raumfahreturschutze
    @raumfahreturschutze 5 днів тому

    The number of bugs in our systems is TOO DAMN HIGH!

  • @user-xe9tr9hf6b
    @user-xe9tr9hf6b 23 дні тому

    More of these videos would be appreciated

  • @leandewxw
    @leandewxw 18 днів тому

    Hacking into someone’s router is the equivalent of “I’m in your walls”

  • @isbestlizard
    @isbestlizard 23 дні тому +22

    Oh another RCE/hard coded credentials vulnerability? Gee Palo Alto you sure do suck tonight.

  • @andljoy
    @andljoy 23 дні тому +5

    We are on an older panos so we are fine :).

  • @signal65
    @signal65 23 дні тому +1

    💥💥💥💥

  • @isbestlizard
    @isbestlizard 23 дні тому +16

    Make a t-shirt with Monero-chan looking cute and I will buy one

    • @susguy446
      @susguy446 23 дні тому +1

      💀

    • @spacemeter3001
      @spacemeter3001 23 дні тому

      He should make one where her bare feet and them toes are visible 😛🦶👡

    • @gamtax
      @gamtax 21 день тому

      I thought he made a bunch long time ago...

  • @jvav
    @jvav 22 дні тому

    couple months ago there was fortinet that had a vulnerability

  • @ENNEN420
    @ENNEN420 21 день тому

    "D-disable telemetry to g-get it to stop? John you're smart, will the breach or disabling telemetry lose us more money?
    "Sir, the telemetry is for just the employees"
    "Then it's more valuable!!!"
    "..."

  • @brotherxam1903
    @brotherxam1903 23 дні тому +10

    hmmm...... Disable Telemetry.......

  • @rlocone
    @rlocone 22 дні тому

    That hacker in the beginning wearing the mask looks like he was mixing and spinning some vinyl.

  • @codemiesterbeats
    @codemiesterbeats 17 днів тому

    Im too easily amused "please like and share it"
    Nice little animation around the like button... Who knows how long this has been a thing but neato

  • @eointhomas2914
    @eointhomas2914 23 дні тому +2

    Any hospital or med facility I go too all have Palo Alto’s 😂

  • @MinuteBracelet
    @MinuteBracelet 23 дні тому +2

    Critical RCE Theory

  • @crazy_dummie5240
    @crazy_dummie5240 23 дні тому +1

    microsoft SSH man is the harambe of the NSA

  • @Gbennett1425
    @Gbennett1425 22 дні тому

    I wonder if this is how my university I go to got hacked into. Whoever it was critically damaged or wiped all the virtual machines and had access to tons of private information.

  • @asddw4998
    @asddw4998 23 дні тому

    GOOD MORNING SIRS PLEASE REMIND TO DO THE NEEDFUL AND SFC /SCANNOW

  • @PiotrPavel
    @PiotrPavel 9 днів тому

    not only Rust, also GO or c# was recomended

  • @GmodFreak555
    @GmodFreak555 22 дні тому

    putty also has a vulnerability discovered where private keys can be exposed

  • @thetransferaccount4586
    @thetransferaccount4586 23 дні тому

    nice one there

  • @goowawa
    @goowawa 23 дні тому

    Vulns in all things held sacred - Linux, Rust, Palo...

  • @rwxzig
    @rwxzig 22 дні тому

    That picture of Biden was epic :D

  • @auroraborealis5565
    @auroraborealis5565 23 дні тому +1

    At the foothills of my IT career, it appears as though cybersecurity might be a viable and secure specialisation?

  • @koensampers5505
    @koensampers5505 22 дні тому

    Quite hilarious that I received multiple alerts at work from this incident lmao

  • @abiram3394
    @abiram3394 23 дні тому +88

    i blame Obama for these bugs

    • @Kabodanki
      @Kabodanki 23 дні тому

      yes obama and the hackers are for sure russians

    • @sn5806
      @sn5806 23 дні тому +9

      I'm still waiting for the medium form birth certificate.

    • @PoposteriousExe-ph5em
      @PoposteriousExe-ph5em 21 день тому

      Aaajhhhhh BuGs 😢

  • @alphaomega154
    @alphaomega154 23 дні тому

    so then the exploit guard needed for this is something that can watch out the use of any commands on CSS file creation, or watching out the vailidity of the CSS creation itself.

  • @jeonghutamilim2259
    @jeonghutamilim2259 22 дні тому

    "Security" products are bigger target than browsers...

  • @z_z
    @z_z 23 дні тому +39

    WEF sponsored code

  • @Nik-rx9rj
    @Nik-rx9rj 23 дні тому

    Yooooooo, another one?!?!?!

  • @OleksandrSe
    @OleksandrSe 17 днів тому

    Oh boy)

  • @HailScreaM77
    @HailScreaM77 22 дні тому

    LOL i have worked in a bank that uses Palo alto Firewall, i wonder if they have telemetry on

  • @abe-danger
    @abe-danger 22 дні тому

    third major bug this month, woo!

  • @DeltaNrOne
    @DeltaNrOne 23 дні тому +1

    Firewall you had 1 job!

  • @lightfox11
    @lightfox11 23 дні тому

    This video is a based win

  • @zyriab5797
    @zyriab5797 22 дні тому +1

    CSS confirmed to be evil

  • @r4ckst7r
    @r4ckst7r 23 дні тому

    The cursed month

  • @Amipotsophspond
    @Amipotsophspond 23 дні тому

    I wonder if you could build a toaster with out it being a smart appliance, do we have the technology or is it just a unattainable dream?

  • @quinniwe
    @quinniwe 22 дні тому

    I don't even use a firewall on any of my GNU systems.

  • @doublesushi5990
    @doublesushi5990 23 дні тому +2

    *1:44*

  • @user-ef1rs5to5y
    @user-ef1rs5to5y 23 дні тому +1

    Can you do a video on kicksecure? Please 🙏

  • @kameronbriggs235
    @kameronbriggs235 22 дні тому

    Once this stuff is used and smarter people integrate into an existing tools with more persistence, good luck.

  • @islantay5795
    @islantay5795 20 днів тому

    Someone please tell me where did 0:21 came from. I have to know that 😭😭😭

  • @tommy_salami108
    @tommy_salami108 23 дні тому +1

    It’s not exactly clear which name corresponds to which colors on the tor t shirts. Specifically confused about moondance and royal.

  • @Archbtw_
    @Archbtw_ 23 дні тому +3

    tf is up with all these vulnerabilities recently?

  • @Max-mj4sp
    @Max-mj4sp 21 день тому

    How is that gonna affect Stock Prices of palo. How big of a deal are we talking about.

  • @pajeetsingh
    @pajeetsingh 23 дні тому

    What's up with series of critical bugs in the last month?
    Are they making cyber false flag for force some laws?
    What's happening?

  • @itswilliamanimate
    @itswilliamanimate 23 дні тому +29

    government agencies stash of exploits getting discovered this month, huh...
    linux exploit giving ring 0
    xz
    poorly escaped strings in windows
    this

    • @awesomecronk7183
      @awesomecronk7183 22 дні тому

      the windows one has been known of for a long time, getting a 10/10 CVE tagged on rust got it very famous very fast

  • @___gg421
    @___gg421 23 дні тому +3

    just assume all your software has vulnerabilities

  • @asmod4n
    @asmod4n 23 дні тому

    Wait, their WEB UI is running on a Read/Write File System? Thats just asking for trouble.

  • @Leo_Aqua
    @Leo_Aqua 23 дні тому

    We have a LOT of 10/10 Critical CVEs these days

  • @kanshank
    @kanshank 23 дні тому +1

    Again ? Are we doing good those days or bad ? not sure.

  • @letsplaywar
    @letsplaywar 23 дні тому

    Can you make a don't mess with taxes shirt? on your store?

  • @lordbarron3352
    @lordbarron3352 22 дні тому

    Tldr: It's because they didn't install McAfee

  • @zdrux
    @zdrux 23 дні тому

    My employer uses PaloAlto and GlobalProtect for our VPN lol

  • @ChuckNorris-lf6vo
    @ChuckNorris-lf6vo 21 день тому

    This product has always been a risky product due to it's surface. So not surprised at all. So why was the WEB port exposed in the first place ?!?! OMG LOL ROFL

  • @crimsonlion100
    @crimsonlion100 23 дні тому +7

    The only thing keeping Java from being destroyed as it deserves is Minecraft. I tell ya, if I never have to use, or see Java again, I will feel true happiness.

    • @zyriab5797
      @zyriab5797 22 дні тому

      Isn't the bedrock edition just Minecraft in C++ because of all the problems the Java edition caused? (Shitty GC, etc)
      You can still find nice MC clones written in other languages as well

    • @crimsonlion100
      @crimsonlion100 21 день тому +1

      @@zyriab5797 No, I will never play that facsimile of what Minecraft is. The thing that made Minecraft great was BECAUSE it was written in a language like Java. Java is EASILY reverse engineered, and easily modded. That must stay in place for me to even consider it. Classicube comes CLOSE, but the fact that they restrict themselves to classic is very very unfortunate. Beta 1.7.3 is and has always been the best version of Minecraft. and things like Glowstone are so incomplete it isnt even worth it.

  • @girlscoutfather6766
    @girlscoutfather6766 21 день тому

    Chat, are we fucked?

  • @JabbaTiure
    @JabbaTiure 23 дні тому

    Build your own Opnsense firewall. Problem sidestepped.

  • @wichu7131
    @wichu7131 23 дні тому

    wsg

  • @froozynoobfan
    @froozynoobfan 21 день тому

    please correct the video, they updated the page, disabeling telemetry does not mitigate the vulnerability!!!

  • @Mr.Beauregarde
    @Mr.Beauregarde 23 дні тому +1

    Hevking first

  • @levigeorge9140
    @levigeorge9140 10 днів тому

    See, the firewall vulnerabilities only affect you if you actually use a firewall. There is only one solution here.

  • @andreassa
    @andreassa 22 дні тому

    Yo Kenny, why the hell does Google say you are a “Musical Artist”? Drop the beats, homie.

  • @hombre356
    @hombre356 23 дні тому

    This is going to keep the cybersecurity team at my company pulling their hair out as we use global protect. Glad I am not them.

    • @zachalam2232
      @zachalam2232 23 дні тому

      Not really… just disable telemetry, apply threat content updates, or upgrade the OS

  • @ASaltyAcc
    @ASaltyAcc 23 дні тому

    Welp lets see this shit

  • @Bagginsess
    @Bagginsess 23 дні тому

    Pullo Alto lol

  • @matthewdouglas2373
    @matthewdouglas2373 23 дні тому

    I think Palo Alto is losing control of their code base maintainability.

  • @yesyesyesgrill-ir2ur
    @yesyesyesgrill-ir2ur 21 день тому

    bro what is going on rn with all the exploits

  • @tetttettamilli6761
    @tetttettamilli6761 22 дні тому

    @MO - "Gay Agenda"

  • @Radical_racist
    @Radical_racist 20 днів тому

    Does firewalls stop ddos

  • @kawalier1
    @kawalier1 22 дні тому

    Which cloud?

  • @markf8819
    @markf8819 23 дні тому +3

    Wow so deep

  • @haythamkenway1561
    @haythamkenway1561 23 дні тому +1

    you really need to take care of your comment section. full of bots and spammers.

  • @immameme
    @immameme 23 дні тому

    Firewall situation and Imma1st
    Don't take my comments seriously. It's only a meme

  • @linuxguy1199
    @linuxguy1199 23 дні тому

    Everybody is getting on the hype train for Rust thinking it's the magic bullet to all their problems. Just like Java was the magic bullet back in the 2010s. It's idiotic to suggest a programming language can be the goto solution for solving security problems in software that is fundamentally not secure.