Wireless Security protocols Evolution

While going through the various Wi-Fi attacks, it’s worthwhile to combine them in a single post. This post discusses about the various Wi-Fi standards that evolved and evolving in networks.…

Forti bugs under Active APT Attack

The FBI today issued a flash alert warning that so-called advanced persistent threat actors are exploiting vulnerabilities in cybersecurity appliances from Fortinet Inc. An APT group has exploited a Fortinet…
Palo Alto Zeroth down

Palo Alto Zeroth down

Palo Alto Networks announced a slate of new features designed to help customers introduce a Zero Trust across their network security stack. The process of adopting complete Zero Trust Network…
FragAttack Haunts Wi-Fi Devicee

FragAttack Haunts Wi-Fi Devicee

FragAttack (Fragmentation and aggregation attack) affect WiFi devices exposed them to remote attacks. The vulnerabilities could be exploited by an attacker within a device’s WiFi radio range to steal info…
CloudFlare New WAF

CloudFlare New WAF

Cloudflare has recently introduced a new Web Application Firewall. The latest engine is written in Rust, provides better performances and integrates with other Cloudflare products. The new implementation was designed…
CLOUDEFENDER

CLOUDEFENDER

Tech Mahindra announced the launch of a new cloud security offering called ‘CLOUDEFENDER.’ cloud based mitigation service The solution is powered by cybersecurity and application delivery solutions provider Radware and…
NAT Slipstream 2.0 Exposes internal servers

NAT Slipstream 2.0 Exposes internal servers

The NAT Slipstreaming attack relies on tricking the victim into accessing a specially crafted website and exploits the browser on the device, along with the Application Level Gateway (ALG), a connection tracking mechanism in Network Address Translation (NAT), firewalls, and routers.

The attack was meant to bypass existing browser-based port restrictions and allow the attacker to remotely access TCP/UDP services on the victim’s device, even if it was protected by a firewall or NAT.

Researches comes with a variant of the attack, dubbed NAT Slipstreaming 2.0, that can bypass mitigations for NAT Slipstreaming, and which also expands the attacker’s reach, allowing them to create paths to any device on the internal network.

This puts embedded, unmanaged, devices at greater risk, by allowing attackers to expose devices located on internal networks, directly to the Internet.

Devices may include printers exposed through the default printing protocol, industrial controllers using unauthenticated protocols, and IP cameras that have an internal web server secured with default credentials. These devices when abused will trigger Ransomware attacks

The new attack is based on new primitives and allows for connections to any destination ports, fully bypassing the mitigations that browser makers have introduced for NAT Slipstreaming.

The attacker needs to craft a website containing malicious code and then trick the victim into accessing that website. The code sends multiple fetch requests from the victim browser on H.323 port (1720), thus allowing the attacker to “iterate through a range of IP addresses and ports, each time opening an IP/port to the Internet,” for reconnaissance.

Fixes for the issue were included in all major web browsers, namely Chrome v87.0.4280.142, Firefox v85.0, and Safari v14.0.3. Microsoft’s Edge, which relies on the Chromium source code, is also patched. The bug is tracked as CVE-2020-16043 in Chromium and CVE-2021-23961 in Firefox.

The mitigations all browser makers added to their software involved making two changes, namely adding the TCP/UDP ports of all known ALGs to the list of restricted ports, and enforcing the list on WebRTC connections as well.

SolarWinds Aftermath !

SolarWinds Aftermath !

SolarWinds hack revelation provides an illustrative and timely example of how cybersecurity vulnerabilities can affect every organization, with the company’s enterprise software, a network monitoring system, installed at government agencies,…