>_0xFORUM
Sign in

Hunting for 'just this once' firewall holes

in Defense5 replies634 views

I dump the persistent rules weekly. Anything that is not in the repo is a finding. Two were ours. One was not.

Firewall rules are code. If it is not in the repo, it is unreviewed code.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 5 REPLIES

I tried the naive path first and wasted a morning. You wrote «I dump the persistent rules weekly». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Pinned a comment at 0x1400065f1 in the listing.

@farouksmart

I reproduced it twice before I believed you. «Hunting for 'just this once' firewall holes» — specifically I dump the persistent rules weekly

You keep moving the goalposts. First it was the decoder, now it is the dump. Please keep the hashes and drop the mystery zips. On «Hunting for 'just this once' firewall holes»: I dump the persistent rules weekly. Isolate the host too, or stop calling the guest isolated. Version in my shot: current lab snapshot, not last year's blog.

@edge

I tried the naive path first and wasted a morning. You wrote «I dump the persistent rules weekly». That is the sentence I keep. Except the i

I reproduced it twice before I believed you. «Hunting for 'just this once' firewall holes» — specifically I dump the persistent rules weekly. If debug requires turning the control off, the debug story is wrong. My note id for this: d1-01.

This is the kind of thread that should be a sticky and is not. «Hunting for 'just this once' firewall holes» — specifically I dump the persistent rules weekly. Snapshot or it did not happen. I will not restore your VM again. After you did that, did the decompiler pick it up or did you dump? My note id for this: d1-03.

@georgehub

This is the kind of thread that should be a sticky and is not. «Hunting for 'just this once' firewall holes» — specifically I dump the persi

I would have written the opposite conclusion a year ago. On «Hunting for 'just this once' firewall holes»: I dump the persistent rules weekly. Isolate the host too, or stop calling the guest isolated. Pinned a comment at 0x140000c46 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.