Before getting too hyped about it though, someone with a Cisco firewall should dig further into it to understand the pre-requirements.
-
-
Replying to @musalbas
BENIGNCERTAIN has three steps for operating it. Step 1: run bc-genpkt to generate a packet to send to a Cisco VPN.pic.twitter.com/ii91qExzVI
1 reply 26 retweets 22 likes -
Replying to @musalbas
Step 2: run bc-id to send the packet to a Cisco VPN target.pic.twitter.com/fGWvlRWLpf
1 reply 23 retweets 17 likes -
Replying to @musalbas
Step 3: run bc-parser to parse the response from the Cisco VPN.pic.twitter.com/XPiYiI8f8E
1 reply 24 retweets 19 likes -
Replying to @musalbas
bc-parser appears to be able to extract RSA private keys and other VPN configuration from the response.
1 reply 20 retweets 19 likes -
Replying to @musalbas
This means NSA's tool may be able to extract Cisco VPN private keys by remotely sending a packet to it. That's huge.pic.twitter.com/uGnjNVKYYh
10 replies 433 retweets 309 likes -
Replying to @musalbas
Again though: someone who has a Cisco firewall should investigate more to verify if this is the case and understand the exact implications.
2 replies 6 retweets 10 likes -
Replying to @musalbas
Does anyone have a Cisco PIX firewall with a VPN configured for me to test on?
8 replies 12 retweets 10 likes -
Replying to @musalbas
Not sure what payload does exactly, it looks like it may be a Heartbleed/overflow-type vulnerability to dump memory.pic.twitter.com/sO8T7SRVSb
3 replies 20 retweets 12 likes -
Replying to @musalbas
I was going to say, it sounds like a Heartbleed style buffer overread or other arbitrary read vuln.
1 reply 1 retweet 0 likes
Looks like it sends IKE packets with a very large Group-Prime option. If the Cisco is replying using the request length (1/2)
-
-
... but only filling in the requested 768 bit prime, then you've got yourself a buffer of uninitialized crap following it (2/2)
2 replies 12 retweets 23 likes -
Replying to @marcan42
It appears to patch memory?pic.twitter.com/JsnhmTEkUW
1 reply 0 retweets 0 likes - Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.