Friday, February 3, 2023
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
Asia Post
No Result
View All Result
  • HOME
  • NEWS
    • INDIA
    • CHINA
    • WORLD
  • DEFENSE
  • POLITICS
  • BUSINESS
  • HEALTH
  • SPORTS
  • ENTRTAINMENT
  • TECHNOLOGY
  • LIFESTYLE
  • TRAVEL
  • OUR TEAM
Asia Post
No Result
View All Result

More than 4,400 Sophos firewall servers remain vulnerable to critical exploits

January 18, 2023
in TECHNOLOGY
0 0
0
Share on FacebookShare on TwitterShare on Email


Photograph depicts a security scanner extracting virus from a string of binary code. Hand with the word

Getty Images

More than 4,400 Internet-exposed servers are running versions of the Sophos Firewall that’s vulnerable to a critical exploit that allows hackers to execute malicious code, a researcher has warned.

CVE-2022-3236 is a code injection vulnerability allowing remote code execution in the User Portal and Webadmin of Sophos Firewalls. It carries a severity rating of 9.8 out of 10. When Sophos disclosed the vulnerability last September, the company warned it had been exploited in the wild as a zero-day. The security company urged customers to install a hotfix and, later on, a full-blown patch to prevent infection.

According to recently published research, more than 4,400 servers running the Sophos firewall remain vulnerable. That accounts for about 6 percent of all Sophos firewalls, security firm VulnCheck said, citing figures from a search on Shodan.

“More than 99% of Internet-facing Sophos Firewalls haven’t upgraded to versions containing the official fix for CVE-2022-3236,” VulnCheck researcher Jacob Baines wrote. “But around 93% are running versions that are eligible for a hotfix, and the default behavior for the firewall is to automatically download and apply hotfixes (unless disabled by an administrator). It’s likely that almost all servers eligible for a hotfix received one, although mistakes do happen. That still leaves more than 4,000 firewalls (or about 6% of Internet-facing Sophos Firewalls) running versions that didn’t receive a hotfix and are therefore vulnerable.”

Advertisement

The researcher said he was able to create a working exploit for the vulnerability based on technical descriptions in this advisory from the Zero Day Initiative. The research’s implicit warning: Should exploit code become public, there’s no shortage of servers that could be infected.

Baines urged Sophos firewall users to ensure they’re patched. He also advised users of vulnerable servers to check for two indicators of possible compromise. The first is the log file located at: /logs/csc.log, and the second is /log/validationError.log. When either contains the_discriminator field in a login request, there likely was an attempt, successful or otherwise, to exploit the vulnerability, he said.

The silver lining in the research is that mass exploitation isn’t likely because of a CAPTCHA that must be completed during authentication by web clients.

“The vulnerable code is only reached after the CAPTCHA is validated,” Baines wrote. “A failed CAPTCHA will result in the exploit failing. While not impossible, programmatically solving CAPTCHAs is a high hurdle for most attackers. Most Internet-facing Sophos Firewalls appear to have the login CAPTCHA enabled, which means, even at the most opportune times, this vulnerability was unlikely to have been successfully exploited at scale.”



Source link

Tags: CriticalexploitsFirewallremainserversSophosVulnerable
ShareTweetSend

Related Posts

TECHNOLOGY

Samsung Galaxy S23 Series First Look Video: Beast Mode?

February 3, 2023
TECHNOLOGY

Senator asks Apple and Google to ban TikTok from their app stores

February 3, 2023
TECHNOLOGY

Hundreds of Salesforce workers laid off in January just discovered they were out of work today • TechCrunch

February 2, 2023
TECHNOLOGY

ISP admits lying to FCC about size of network to block funding to rivals

February 2, 2023
TECHNOLOGY

Docs: Verily's revenue grew to $470M in the first nine months of 2022, up from $228M YoY, making the company Alphabet's second biggest subsidiary by revenue (Jon Victor/The Information)

February 2, 2023
TECHNOLOGY

TRAI to Meet Jio, Airtel and Other Telcos on February 17 to Discuss Plan for Improvement in Services

February 2, 2023
Load More
Next Post

Microsoft to cut engineering jobs this week as layoffs go deeper: Report

Winning Numbers for January 18 Satta King Games

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest

Air Force To Upgrade Sukhoi Jets For 4 Billion Dollar To Increase Its Capacity And Capability

January 26, 2023

7 killed, over 400 injured as 5.9 magnitude earthquake rocks northwest Iran

January 29, 2023

I-T dept conducts survey action against Cipla, Health News, ET HealthWorld

January 31, 2023

French Navy Ship Marne on Goodwill Visit to Mumbai

January 28, 2023

Full Emergency Declared at Abu Dhabi Airport for Air India Aircraft With Engine on Fire; Flight Lands Safely

February 3, 2023

5.9 Magnitude Earthquake Hits Turkey-Iran Border, 2 Killed: Report

January 28, 2023

india: Neglected tropical diseases continue to pose significant health burden in India: Expert

January 30, 2023

Vijay’s Varisu to release on Amazon Prime Video on this date

February 1, 2023

Shah Rukh Khan Starrer Pathaan Continues To Rule, Earns Rs 700 Cr Globally in 9 Days

February 3, 2023

Karnataka announces 50% rebate for e-challan traffic violation cases till February 11

February 3, 2023

‘Faraaz’ movie review: Hansal Mehta’s film hangs between hope and hell and stands up to bigotry  

February 3, 2023

China Warns Against ‘Hype’, Says Working to ‘Verify’ Reports it Flew Spy Balloon Over US

February 3, 2023

These are the consequences if you indulge in malpractices during board exams: Maharashtra state board to students

February 3, 2023

Covid-19L China Lifts Curbs To Fully Resume Travel With Hong Kong, Macau From February 6

February 3, 2023

BBC documentary: Supreme Court issues notice to Centre | India News

February 3, 2023

TomTom raises 2023 revenue outlook as automotive drives Q4 beat | China Breaking News | Top Stories | Political | Business | Entertainment

February 3, 2023
Asia Post

Get the latest news and follow the coverage of breaking news, local news, national, politics, and more from the Asia's top trusted sources.

Categories

  • BUSINESS
  • CHINA
  • DEFENSE
  • ENTRTAINMENT
  • HEALTH
  • INDIA
  • INDIA-NORTHEAST
  • LIFESTYLE
  • POLITICS
  • SPORTS
  • TECHNOLOGY
  • TRAVEL
  • WORLD

Recent News

  • Shah Rukh Khan Starrer Pathaan Continues To Rule, Earns Rs 700 Cr Globally in 9 Days
  • Karnataka announces 50% rebate for e-challan traffic violation cases till February 11
  • ‘Faraaz’ movie review: Hansal Mehta’s film hangs between hope and hell and stands up to bigotry  
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Our Team
  • Contact

Copyright © 2021 Asia Post.
Asia Post is not responsible for the content of external sites.

No Result
View All Result
  • HOME
  • NEWS
    • INDIA
    • CHINA
    • WORLD
  • DEFENSE
  • POLITICS
  • BUSINESS
  • HEALTH
  • SPORTS
  • ENTRTAINMENT
  • TECHNOLOGY
  • LIFESTYLE
  • TRAVEL
  • OUR TEAM

Copyright © 2021 Asia Post.
Asia Post is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In