Friday, May 24, 2024

Skyguard Proxy support running on Tencent Cloud

 








Print Friendly and PDF
Share/Bookmark

Sunday, May 19, 2024

CVE-2024-3661 - Workaround and Mitigation

On May 6, 2024, a researcher from Leviathan Security Group identified a new technique, termed as "TunnelVision", that can bypass VPN encapsulation and enable attackers to send the traffic outside a VPN tunnel using the built-in features of Dynamic Host Configuration Protocol (DHCP). TunnelVision involves the routing of traffic without encryption through a VPN. This traffic can be directed by the attacker's configured DHCP server using option 121, ultimately being redirected to the internet via a side channel created by the attacker. The existing VPN tunnel remains intact, and the side channel created by the attacker cannot be detected by the existing VPN tunnel. CVE-2024-3661 has been assigned to this critical vulnerability.

Workaround and Mitigation advise:
1. Instead of using public WiFi network, use a mobile hotspots for VPN connection
2. In hotel, instead of using hotel Wired or WiFi network directly, use a travel router to connect to hotel wired network, then use this network for VPN connection
3. Using a Virtual machine for VPN connection

Reference:





Print Friendly and PDF
Share/Bookmark

Fix Google Chrome update failed Error 7

Error: 
There are Google Chrome update failed Error 7:

Solution:
Need to able to access tools.google.com and dl.google.com


Reference:

Print Friendly and PDF
Share/Bookmark

How to find which Access Point (AP) connected on Windows 10 / 11?

To find a AP which is your laptop connected, you can run the following command:

netsh wlan show in

There is 1 interface on the system:

    Name                   : Wi-Fi
    Description            :
    GUID                   : 
    Physical address       : 
    State                  : connected
    SSID                   : 
    BSSID                  : <This is the MAC address of the AP you connected>
    Network type           : Infrastructure
    Radio type             : 802.11n
    Authentication         : 
    Cipher                 : 
    Connection mode        : Auto Connect
    Channel                : 
    Receive rate (Mbps)    : 
    Transmit rate (Mbps)   : 
    Signal                 : %
    Profile                : 

    Hosted network status  : Not available

Print Friendly and PDF
Share/Bookmark

Friday, April 26, 2024

Hackers backdoored Cisco ASA devices via two zero-days (CVE-2024-20353, CVE-2024-20359)

  1. Upgrade your Cisco ASA to the below versions: (Depend on your Cisco ASA support which version)
    9.16.4.57
    9.18.4.22
    9.20.2.10
  2. Check your firewall log or SIEM to see if there are any IOC IP hit your log.

For more detail of the IOC, please check:

Check your Cisco ASA compatibility:


Reference:

Print Friendly and PDF
Share/Bookmark

Wednesday, April 24, 2024

H3C firewall SSL weak cipher

Nessus vulnerability scan report about H3C firewall SSL weak cipher 

Go to "Objects" -> "SSL" -> "SSL Server Policies"

You will found that even you select "TLS 1.2" and Cipher suites "High level":

SSL_RSA_with_AES_128_CBC_SHA

SSL_RSA_with_AES_256_CBC_SHA


You still false in the security scanning report and it will show weak cipher.

Solution:

Use the following 4 Cipher:

 

https://www.tenable.com/plugins/nessus/156899 


After change the cipher under firewall GUI, then SSH to the firewall

 

> system-view

 

] undo ip https enable

 

] ip https enable

 

] save force

 

] exit

 

>

 

Print Friendly and PDF
Share/Bookmark

Saturday, April 20, 2024

H3C Firewall Change admin portal certificate

1. Go to H3C Firewall -> SSL -> SSL Server Policies to create a new Policy e.g. "abc_2024-2026"

2. Create a PKI Domain for new cert installation

3. Go to PKI -> Certificate -> Import 2 CA cert and 1 local cert

CA to provide TWO CA cert (.cer) (When install second CA, just ignore the cert will be replace warning) and One local cert (.pfx) (RSA 2048) (This local cert need to includ private key and also ignore the cert will be replace warning)

4. SSH to the firewall 
 > show current-configuration (Enable logging on putty before run this command) 
 > system-view ] undo ip https enable 
 ] ip https ssl-server-policy <New Policy Name which is you create at step1> 
 ] ip https enable 
 ] save force 
 ] exit 
 >

Print Friendly and PDF
Share/Bookmark