Post B647ZFckQmeG6pfksC by srslypascal@chaos.social
 (DIR) More posts by srslypascal@chaos.social
 (DIR) Post #B63twADHJd5Cd7n5QO by malwaretech@infosec.exchange
       0 likes, 1 repeats
       
       I found a zero day in a security vendor's firewall software that allows you to remotely crash the entire system by sending it a single malicious packet. Since the firewall is responsible for inspecting traffic prior to the operating system handling it, no ports even need to be open for it to work.
       
 (DIR) Post #B63u3gSHq3yeecOeW0 by azonenberg@ioc.exchange
       0 likes, 0 repeats
       
       @malwaretech NO ports? That is impressive.The last DoS I found in a firewall needed port 80 to be open to something behind it since it was related to WAF stuff
       
 (DIR) Post #B63uI2szEs9oH9jXhA by tux0r@layer8.space
       0 likes, 0 repeats
       
       @malwaretech Ah, the joys of "security" software.
       
 (DIR) Post #B63uMTglWomWYt8AKG by rgsteele@toque.town
       0 likes, 0 repeats
       
       @malwaretech WinNuke 2026! ☢️
       
 (DIR) Post #B63uOFPXaGMarJuxkW by erik@mastodon.infrageeks.social
       0 likes, 0 repeats
       
       @malwaretech The ping of death is back!
       
 (DIR) Post #B63udpgyyOINj9VX3A by bontchev@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech You should have waited till Friday. That's the Vulnerability Disclosure Day, isn't it?
       
 (DIR) Post #B63v4UbpT3MC9qoG0m by jamesmarshall@sfba.social
       0 likes, 0 repeats
       
       @malwaretech reminds me of the 1990s (?) dirt-simple exploit whereby you could crash a Windows machine merely by sending it any OOB packet.  Yes, I tried it and it worked.  I later saw code for it in an exhibit of various exploits at Madrid's Reina Sofia art museum.  Cool exhibit.Edit:  Found it-- it was called WinNuke.https://en.wikipedia.org/wiki/WinNuke
       
 (DIR) Post #B63w0rd22XfKLaCopU by simonzerafa@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech Did you use your "AI" workflow to discover this? 🙂
       
 (DIR) Post #B63wBrVqoL9bAo5iK0 by Elmar_Iachi@chaos.social
       0 likes, 0 repeats
       
       @malwaretech Fuzzy packet?
       
 (DIR) Post #B63x8Hi9Z17jDphgMC by Rimuru@s.cafe
       0 likes, 0 repeats
       
       @malwaretech Get yourself paid for your discovery.  Microsoft pays people who finds exploits.  Often people report this in the wild, and lose out being paid.— edit —I am clearly not sleeping well.  I thought this had to do with Windows firewall and not a 3rd party vendor.  Oops!https://www.microsoft.com/en-us/msrc/bounty
       
 (DIR) Post #B647ZFckQmeG6pfksC by srslypascal@chaos.social
       0 likes, 0 repeats
       
       @malwaretech You mean they built their firewall out of jerrycans?
       
 (DIR) Post #B649aTjxdFeQ5Wl91s by mrencyclopedia@retro.pizza
       0 likes, 0 repeats
       
       @malwaretech Reminds me of the good old days of Winnuke
       
 (DIR) Post #B64AbHkHoVer8ArO9w by robloblaw@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech The latest darknet diaries podcast has a wild story of Chinese state sponsor APT attacks on firewall makers.https://darknetdiaries.com/episode/174/The response from Sophos was even wilder.
       
 (DIR) Post #B64Cy4KQ43cc5RkjsO by gary_alderson@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech did you find this with your ai vuln pipeline? don't stop there, build a company out of it #flavor dust shortage
       
 (DIR) Post #B64H9gXkioFTbvmfLM by SpaceLifeForm@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech I'll bet if you keep trying, you will find the Magic Packet (likely a sequence of 2) that will lead to a root shell.
       
 (DIR) Post #B64zwSVw4DFqGx09JI by hitem@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech lol.py