Тёмный

Zero Day Bug Found in Popular Firewalls 

Mental Outlaw
Подписаться 671 тыс.
Просмотров 62 тыс.
50% 1

Опубликовано:

 

27 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 234   
@jonahkrompart
@jonahkrompart 5 месяцев назад
It’s hilarious that this takes place over the device telemetry channel, AKA the spyware that Palo Alto highly encourages you to not opt out of
@JacobyB
@JacobyB 5 месяцев назад
because it collects errors 🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯
@LailSidgar
@LailSidgar 5 месяцев назад
@@JacobyB It collects errors. Good thing bugs are features and not errors.
@ARCNSPUDS
@ARCNSPUDS 5 месяцев назад
It doesn’t matter if telemetry is on or not
@jonahkrompart
@jonahkrompart 5 месяцев назад
@@ARCNSPUDS Palo specifically recommended in their advisory that you disable telemetry to mitigate the issue, I’m sure you know better than them
@kilosandkeyboards
@kilosandkeyboards 5 месяцев назад
@@jonahkrompart Nah, there was an update from PANW which states that telemetry does not need to be enabled for this CVE to be exploited.
@EmM-ko7mu
@EmM-ko7mu 5 месяцев назад
whats with all the vulnerabilities being found this month
@symbioticparasite6268
@symbioticparasite6268 5 месяцев назад
Jacky be hacky
@archimedesbird3439
@archimedesbird3439 5 месяцев назад
@@johnsmith8981 Stop deifying AI, it's a tech bubble fed by illegally scraped data and nothing more.
@vigilantmug5028
@vigilantmug5028 5 месяцев назад
Better than feds and other "cyber security specialists" exploiting them as zero days under the radar
@dogyX3
@dogyX3 5 месяцев назад
The XZ exploit sparked everyone to check their defences again.
@MaxiTimmi
@MaxiTimmi 5 месяцев назад
@@johnsmith8981 I am sure cyber security companies would be able to use AI as well for their systems so it's unlikely that would happen
@Jango1989
@Jango1989 5 месяцев назад
That feeling when the firewall glows brighter than the fire...
@88Based88
@88Based88 5 месяцев назад
State sponsored threat actors seething hard rn.
@Immortal-market
@Immortal-market 5 месяцев назад
This
@TheSuperBoyProject
@TheSuperBoyProject 5 месяцев назад
No, I am fine
@spacemeter3001
@spacemeter3001 5 месяцев назад
​@@TheSuperBoyProjectBeing on unemployment benefits doesn't count as "state sponsored"
@88Based88
@88Based88 5 месяцев назад
@@spacemeter3001 topkek
@jakedhale
@jakedhale 5 месяцев назад
@@spacemeter3001 lmao gg
@zaremol2779
@zaremol2779 5 месяцев назад
This isn't a 0-day, this is an alphabet soup agency backdoor
@Daniel-sj2mu
@Daniel-sj2mu 5 месяцев назад
It was over for Palo Alto once Professor Messer stopped working there
@fiverZ
@fiverZ 5 месяцев назад
Context?
@YaySyu
@YaySyu 5 месяцев назад
Don't worry, my firewall has a firewall.
@Exigentable
@Exigentable 5 месяцев назад
good luck pal i'm 7 firewalls deep
@marconiandcheese7258
@marconiandcheese7258 5 месяцев назад
Yo dawg I heard you liked firewalls so I got your firewall a firewall
@necktwister666
@necktwister666 5 месяцев назад
firewall²
@nitproject5193
@nitproject5193 5 месяцев назад
it doesn't matter if they are on a same network and one of them can be compromized
@elpsykongr00
@elpsykongr00 5 месяцев назад
Firecube
@hvher
@hvher 5 месяцев назад
Month of vulnurabs
@Alfred-Neuman
@Alfred-Neuman 5 месяцев назад
Yeah wtf is happening?
@juho1882
@juho1882 5 месяцев назад
​@@Alfred-Neumanthese are found all the time. people have just been making more videos of them lately
@adrianfisher3349
@adrianfisher3349 5 месяцев назад
I wanted an enterprise grade firewall for my home network so I could gain work experience with it. I couldn't afford any of them I saw and then loads of flaws in them were announced. I then bought a workstation/server and installed OpenBSD on it and love it.
@adrianfisher3349
@adrianfisher3349 5 месяцев назад
@GhOs7-Operator WiFi isn't very good under OBSD but I used an old Asus router for that, which is connected to my firewall though and Ethernet cable and I have no problems there either. I put 16GB ECC RAM in (this was 2015) which I know is much more than would be needed but it let me setup part of it as a RAM disk so the SSD drive is almost only used during boot ups and software updates to help it last longer.
@sampatton146
@sampatton146 5 месяцев назад
Back door insisted by the glowies
@hakawatis
@hakawatis 5 месяцев назад
in 2016 we were only discovering maybe 10K-30K CVE's a year. in 2022 we were discovering 100,000 CVEs a year. in 2024 we're discovering 4x the amount of CVEs a year. goodluck blue team. this year is gonna be hell for you. 😭😭
@rohanofelvenpower5566
@rohanofelvenpower5566 5 месяцев назад
get out of infosec, its an overworked industry and it will only get worse. bad career choice. like videogaming industry.
@syedibrahimkhalil786
@syedibrahimkhalil786 5 месяцев назад
@@rohanofelvenpower5566 lol with that mindset, I wonder what insecure world would we live in then. This actually give a survival bias, where in actual there is 'more' need of infosec than running out of it.
@markmonster3315
@markmonster3315 5 месяцев назад
@@rohanofelvenpower5566 Isn't that exactly the reason to get into it?
@rj7250a
@rj7250a 5 месяцев назад
​@@markmonster3315if you enjoy regular overtime, 10 hours shifts, sometimes and earning 5x less than some dude typing SQL commands at a bank for 10 hours a week, sure. That is basically game dev industry, that is why i always say to new programmers to not do game dev. I do not know about cybersec industry, maybe it is not as bad, since it is more boring than game dev. The pay and working conditions of a programming job is proportional to how boring it is. - me, 2024
@lokeshchandak3660
@lokeshchandak3660 5 месяцев назад
​@@rj7250aso the more boring something is, the better the pay and the better the work conditions? I have a feeling you meant to say inversely proportional...
@jer1776
@jer1776 5 месяцев назад
TLDR: Your firewall should have a firewall
@deadshxll
@deadshxll 5 месяцев назад
funnily enough, the Security+ certificate which is considered fundamental cert, provided by CompTIA, actually calls out that security controls themselves have the possibility to be vulnerable and open to attack vectors.
@chubbycatfish4573
@chubbycatfish4573 5 месяцев назад
It's always something, isn't it?
@_ruddegar
@_ruddegar 5 месяцев назад
Keeps me employed!
@dinguscollective1872
@dinguscollective1872 5 месяцев назад
@@_ruddegar pretty much why this shit is happening lmao. more jobs I guess
@_ruddegar
@_ruddegar 5 месяцев назад
@dinguscollective1872 lol you might be on to something.
@ditrypand8273
@ditrypand8273 5 месяцев назад
oh that swag "Won't fix" still gives me chuckle
@raumfahreturschutze
@raumfahreturschutze 4 месяца назад
The number of bugs in our systems is TOO DAMN HIGH!
@bradbeckett
@bradbeckett 4 месяца назад
It’s very obvious all these remote root backdoors are not simply accidents anymore.
@evccyr
@evccyr 5 месяцев назад
Vulnerabilities playing April fools the entire month
@andljoy
@andljoy 5 месяцев назад
We are on an older panos so we are fine :).
@BJ-sq1si
@BJ-sq1si 5 месяцев назад
Your security vulnerability discovery videos are my favorite
@tommy_salami108
@tommy_salami108 5 месяцев назад
It’s not exactly clear which name corresponds to which colors on the tor t shirts. Specifically confused about moondance and royal.
@Archbtw_
@Archbtw_ 5 месяцев назад
tf is up with all these vulnerabilities recently?
@a_spe_ct
@a_spe_ct 5 месяцев назад
WEF sponsored code
@saltypureblood8987
@saltypureblood8987 5 месяцев назад
First you fix zee bugs, then you eat zee bugs.
@Max-mj4sp
@Max-mj4sp 5 месяцев назад
How is that gonna affect Stock Prices of palo. How big of a deal are we talking about.
@Gbennett1425
@Gbennett1425 5 месяцев назад
I wonder if this is how my university I go to got hacked into. Whoever it was critically damaged or wiped all the virtual machines and had access to tons of private information.
@rlocone
@rlocone 5 месяцев назад
That hacker in the beginning wearing the mask looks like he was mixing and spinning some vinyl.
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 5 месяцев назад
Looooool
@GmodFreak555
@GmodFreak555 5 месяцев назад
putty also has a vulnerability discovered where private keys can be exposed
@MinuteBracelet
@MinuteBracelet 5 месяцев назад
Critical RCE Theory
@ENNEN420
@ENNEN420 5 месяцев назад
"D-disable telemetry to g-get it to stop? John you're smart, will the breach or disabling telemetry lose us more money? "Sir, the telemetry is for just the employees" "Then it's more valuable!!!" "..."
@PiotrPavel
@PiotrPavel 5 месяцев назад
not only Rust, also GO or c# was recomended
@crimsonlion100
@crimsonlion100 5 месяцев назад
The only thing keeping Java from being destroyed as it deserves is Minecraft. I tell ya, if I never have to use, or see Java again, I will feel true happiness.
@zyriab5797
@zyriab5797 5 месяцев назад
Isn't the bedrock edition just Minecraft in C++ because of all the problems the Java edition caused? (Shitty GC, etc) You can still find nice MC clones written in other languages as well
@crimsonlion100
@crimsonlion100 5 месяцев назад
@@zyriab5797 No, I will never play that facsimile of what Minecraft is. The thing that made Minecraft great was BECAUSE it was written in a language like Java. Java is EASILY reverse engineered, and easily modded. That must stay in place for me to even consider it. Classicube comes CLOSE, but the fact that they restrict themselves to classic is very very unfortunate. Beta 1.7.3 is and has always been the best version of Minecraft. and things like Glowstone are so incomplete it isnt even worth it.
@lukeskywalker2116
@lukeskywalker2116 5 месяцев назад
Nice walkthrough. Thank you.
@codemiesterbeats
@codemiesterbeats 5 месяцев назад
Im too easily amused "please like and share it" Nice little animation around the like button... Who knows how long this has been a thing but neato
@islantay5795
@islantay5795 5 месяцев назад
Someone please tell me where did 0:21 came from. I have to know that 😭😭😭
@pajeetsingh
@pajeetsingh 5 месяцев назад
What's up with series of critical bugs in the last month? Are they making cyber false flag for force some laws? What's happening?
@denerlkonig277
@denerlkonig277 5 месяцев назад
Thank you for the video
@nasimfaheemalquadir
@nasimfaheemalquadir 5 месяцев назад
I don't even use a firewall on any of my GNU systems.
@alphaomega154
@alphaomega154 5 месяцев назад
so then the exploit guard needed for this is something that can watch out the use of any commands on CSS file creation, or watching out the vailidity of the CSS creation itself.
@User-o5l2w
@User-o5l2w 5 месяцев назад
Can you do a video on kicksecure? Please 🙏
@___gg421
@___gg421 5 месяцев назад
just assume all your software has vulnerabilities
@QuantumKurator
@QuantumKurator 5 месяцев назад
Vulns in all things held sacred - Linux, Rust, Palo...
@zyriab5797
@zyriab5797 5 месяцев назад
CSS confirmed to be evil
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 5 месяцев назад
Yes 😅
@JoeDueterte
@JoeDueterte 5 месяцев назад
More of these videos would be appreciated
@kanshank
@kanshank 5 месяцев назад
Again ? Are we doing good those days or bad ? not sure.
@koensampers5505
@koensampers5505 5 месяцев назад
Quite hilarious that I received multiple alerts at work from this incident lmao
@rwxzig
@rwxzig 5 месяцев назад
That picture of Biden was epic :D
@asddw4998
@asddw4998 5 месяцев назад
GOOD MORNING SIRS PLEASE REMIND TO DO THE NEEDFUL AND SFC /SCANNOW
@DeltaNrOne
@DeltaNrOne 5 месяцев назад
Firewall you had 1 job!
@kameronbriggs235
@kameronbriggs235 5 месяцев назад
Once this stuff is used and smarter people integrate into an existing tools with more persistence, good luck.
@andreassa
@andreassa 5 месяцев назад
Yo Kenny, why the hell does Google say you are a “Musical Artist”? Drop the beats, homie.
@levigeorge9140
@levigeorge9140 5 месяцев назад
See, the firewall vulnerabilities only affect you if you actually use a firewall. There is only one solution here.
@kawalier1
@kawalier1 5 месяцев назад
Which cloud?
@Not_cee
@Not_cee 5 месяцев назад
Does firewalls stop ddos
@girlscoutfather6766
@girlscoutfather6766 5 месяцев назад
Chat, are we fucked?
@tetttettamilli6761
@tetttettamilli6761 5 месяцев назад
@MO - "Gay Agenda"
@lordbarron3352
@lordbarron3352 5 месяцев назад
Tldr: It's because they didn't install McAfee
@signal65
@signal65 5 месяцев назад
💥💥💥💥
@n6ra
@n6ra 5 месяцев назад
The cursed month
@TCKRDefense
@TCKRDefense 5 месяцев назад
Can you make a don't mess with taxes shirt? on your store?
@OleksandrSe
@OleksandrSe 5 месяцев назад
Oh boy)
@doublesushi5990
@doublesushi5990 5 месяцев назад
*1:44*
@JabbaTiure
@JabbaTiure 5 месяцев назад
Build your own Opnsense firewall. Problem sidestepped.
@Heisenberg355
@Heisenberg355 5 месяцев назад
When you say the letter "s" its really loud and sharp. You need a pop filter or edit it in post, its unbearable at loud volume
@matthewdouglas2373
@matthewdouglas2373 5 месяцев назад
I think Palo Alto is losing control of their code base maintainability.
@thetransferaccount4586
@thetransferaccount4586 5 месяцев назад
nice one there
@ads-baisgreenock9737
@ads-baisgreenock9737 2 месяца назад
I dont use a firewall ..i dont use AV my password is the same across all my devices and has been since i was online.. i just hope haxxors see my pathetic shit and move on to somwone more interesting. Is rather be hacked by BH oe RH than have an active attack from NSA or whatever tho.
@ASaltyAcc
@ASaltyAcc 5 месяцев назад
Welp lets see this shit
@Mr.Beauregarde
@Mr.Beauregarde 5 месяцев назад
Hevking first
@wichu7131
@wichu7131 5 месяцев назад
wsg
@Bagginsess
@Bagginsess 5 месяцев назад
Pullo Alto lol
@EricS-uf9mv
@EricS-uf9mv 5 месяцев назад
This is a $200,000-$500,000 product. And that doesn't even include the annual support agreement that's required to purchase the HW, easily another $10k/mo. I seriously doubt even 0.5% of your audience has ANY administrative control over any of these affected network appliances. And if they do, they're certainly already aware of the vulnerability and have 24/7 on-site vendor incident support. For the rest of us tourists, including myself, none of the info you're presenting here is actionable. Therefore it's basically a waste of time.
@itista7
@itista7 5 месяцев назад
I think understanding the depth of what's going on is never a waste of time and you are wrong regarding the part of "0.5 % of the audience has any administrative control over any of those affected network appliances", I used to work at a very large mssp and we managed a lot of these devices for a lot of customers.
@Jimbobsurvives
@Jimbobsurvives 5 месяцев назад
We know you work for the glowies unsubscribed a while ago and asked RU-vid to stop recommending yet I still see every video you upload at the top of my feed
@FuckYoutubeCensorshipCunts
@FuckYoutubeCensorshipCunts 5 месяцев назад
😂 explain
@Zelly2001
@Zelly2001 5 месяцев назад
How does he work for them?
@filthyfrankblack4067
@filthyfrankblack4067 5 месяцев назад
Nobody safe.
@brotherxam1903
@brotherxam1903 5 месяцев назад
hmmm...... Disable Telemetry.......
@awesomecronk7183
@awesomecronk7183 5 месяцев назад
who'da thunk?
@muffinspuffinsEE
@muffinspuffinsEE 5 месяцев назад
HackAttack, from the documents. XD next step is ...
@jonahhekmatyar
@jonahhekmatyar 5 месяцев назад
NSA must be seething this month
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 5 месяцев назад
Lol
@JosephValentine-o5w
@JosephValentine-o5w 5 месяцев назад
Seeding***
@deef0
@deef0 5 месяцев назад
I work in cybersec, got this one on my desk under NDA very late march. Patch was out when they announced it to the rest
@isbestlizard
@isbestlizard 5 месяцев назад
Oh another RCE/hard coded credentials vulnerability? Gee Palo Alto you sure do suck tonight.
@abiram3394
@abiram3394 5 месяцев назад
i blame Obama for these bugs
@Kabodanki
@Kabodanki 5 месяцев назад
yes obama and the hackers are for sure russians
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 5 месяцев назад
Aaajhhhhh BuGs 😢
@imjonkatz
@imjonkatz 5 месяцев назад
When you wonder if it's a bug or a feature...
@JacobyB
@JacobyB 5 месяцев назад
???
@gandalfdaking
@gandalfdaking 5 месяцев назад
Schizo moment
@cunjoz
@cunjoz 5 месяцев назад
@@gandalfdaking glowie moment
@ruthlessadmin
@ruthlessadmin 5 месяцев назад
I'm responsible for a pair of Fortigate appliances. We've had to patch out vulnerabilities before but we generally stay on top of it. While we are attacked relentlessly and constantly, we've so far never had a breech (at least not that we know of yet). What's frustrating, is I can't get upper management to take anything seriously, so we have a weak backup policy and no budget to do anything.
@spacemeter3001
@spacemeter3001 5 месяцев назад
They'll learn once they get compromised
@chimagamer4157
@chimagamer4157 5 месяцев назад
Maybe sell it to them like an insurance policy, you rather pay some money in order not to become bankrupt, incase it does go bad Because this would be the worst possible outcome.
@dracula7779
@dracula7779 5 месяцев назад
@@spacemeter3001 hopefully, but some still don't
@Silentguy_
@Silentguy_ 5 месяцев назад
I manage one at work and a personal one at home. We’ve closed off as much as we can and enabled 2FA on basically everything but with how bad exploits have gotten over the past few years, I take a zero tolerance policy towards updating. If a new update drops, I send out a email saying internet will be offline for about 5 minutes at the end of the day and the only one that can tell me any different is my boss’s boss.
@isbestlizard
@isbestlizard 5 месяцев назад
Make a t-shirt with Monero-chan looking cute and I will buy one
@susguy446
@susguy446 5 месяцев назад
💀
@spacemeter3001
@spacemeter3001 5 месяцев назад
He should make one where her bare feet and them toes are visible 😛🦶👡
@gamtax
@gamtax 5 месяцев назад
I thought he made a bunch long time ago...
@itswilliamanimate
@itswilliamanimate 5 месяцев назад
government agencies stash of exploits getting discovered this month, huh... linux exploit giving ring 0 xz poorly escaped strings in windows this
@awesomecronk7183
@awesomecronk7183 5 месяцев назад
the windows one has been known of for a long time, getting a 10/10 CVE tagged on rust got it very famous very fast
@eointhomas2914
@eointhomas2914 5 месяцев назад
Any hospital or med facility I go too all have Palo Alto’s 😂
@haythamkenway1561
@haythamkenway1561 5 месяцев назад
you really need to take care of your comment section. full of bots and spammers.
@crazy_dummie5240
@crazy_dummie5240 5 месяцев назад
microsoft SSH man is the harambe of the NSA
@linuxguy1199
@linuxguy1199 5 месяцев назад
Everybody is getting on the hype train for Rust thinking it's the magic bullet to all their problems. Just like Java was the magic bullet back in the 2010s. It's idiotic to suggest a programming language can be the goto solution for solving security problems in software that is fundamentally not secure.
@froozynoobfan
@froozynoobfan 5 месяцев назад
please correct the video, they updated the page, disabeling telemetry does not mitigate the vulnerability!!!
@ads-baisgreenock9737
@ads-baisgreenock9737 2 месяца назад
Dont use firewalls AV bs ....people they dont need your phone keyboard , mic , camera as intel now ....remote neural monitoring is here
@dimasskarabas
@dimasskarabas 5 месяцев назад
Hacking into someone’s router is the equivalent of “I’m in your walls”
@yesyesyesgrill-ir2ur
@yesyesyesgrill-ir2ur 5 месяцев назад
bro what is going on rn with all the exploits
@zdrux
@zdrux 5 месяцев назад
My employer uses PaloAlto and GlobalProtect for our VPN lol
@jeonghutamilim2259
@jeonghutamilim2259 5 месяцев назад
"Security" products are bigger target than browsers...
@HailScreaM77
@HailScreaM77 5 месяцев назад
LOL i have worked in a bank that uses Palo alto Firewall, i wonder if they have telemetry on
@jvav
@jvav 5 месяцев назад
couple months ago there was fortinet that had a vulnerability
@asmod4n
@asmod4n 5 месяцев назад
Wait, their WEB UI is running on a Read/Write File System? Thats just asking for trouble.
@Amipotsophspond
@Amipotsophspond 5 месяцев назад
I wonder if you could build a toaster with out it being a smart appliance, do we have the technology or is it just a unattainable dream?
@Leo_Aqua
@Leo_Aqua 5 месяцев назад
We have a LOT of 10/10 Critical CVEs these days
@immameme
@immameme 5 месяцев назад
Firewall situation and Imma1st Don't take my comments seriously. It's only a meme
@lightfox11
@lightfox11 5 месяцев назад
This video is a based win
Далее
Bad OPSEC - How The Feds Traced a Monero User
13:55
Просмотров 548 тыс.
Worlds Dumbest Darknet Admin Gets Busted
14:54
Просмотров 428 тыс.
Witch changes monster hair color 👻🤣 #shorts
00:51
Я ИДЕАЛЬНО ПОЮ
00:31
Просмотров 584 тыс.
Magnetite Mining
16:20
Просмотров 15 тыс.
This DarkWeb Market is Doing an INSANE Exit Scam
12:57
Просмотров 252 тыс.
NEVER install these programs on your PC... EVER!!!
19:26
How Tor Users Get Caught By Saying Too Much
13:41
Просмотров 518 тыс.
Microsoft Is Decrypting Your Files in The Cloud
8:14
Просмотров 233 тыс.
How SUDO on Linux was HACKED! // CVE-2021-3156
19:56
Просмотров 201 тыс.
How To Secure and Anonymize Your Online Activity
25:10
Просмотров 466 тыс.
one of the craziest exploits i've ever seen
8:40
Просмотров 382 тыс.