Get a Pentest and security assessment of your IT network.

News

Attacking SSL VPN – Part 1: PreAuth RCE on Palo Alto GlobalProtect, with Uber as Case Study!

Palo Alto’s GlobalProtect SSL VPN product line is vulnerable to a simple format string vulnerability with no authentication required! The sslmgr is the SSL gateway handling the SSL handshake between the server and clients. There is no output for this format string so that we can’t obtain any address-leak to verify the bug. All the GlobalProtect before July 2018 are vulnerable! Here is the affect version list:. The series 9.0x and 7.1x are not affected by this vulnerability.”]

Source: https://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

A young hacker violated the CIA Directors private AOL email

News

Facebook Bug #4: Password Reset Vulnerability Found in www.facebook.com