this post was submitted on 04 Jan 2025
122 points (100.0% liked)

Cybersecurity - Memes

2411 readers
3 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
122
submitted 2 months ago* (last edited 2 months ago) by [email protected] to c/[email protected]
 

Fortinet, Palo, Checkpoint, Cisco, Sonicwall ... is there any big firewall vendor that didn't have any critical vulnerabilities last year?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 31 points 2 months ago (3 children)

Obsolete binaries not updated for years, hardcoded secrets… this is what you get in firewalls like any other piece of black box equipment.

[–] [email protected] 21 points 2 months ago (1 children)

Security by obscurity may work in delaying exploits, but once someone breaks the obscurity, they have a headstart on exploiting it over those hoping to fix it.

[–] [email protected] 16 points 2 months ago (1 children)

Security by old software, or how I call it: the ivanti approach

[–] [email protected] 12 points 2 months ago

That makes me nervous, but I'm not allowed to tell you why

[–] [email protected] 7 points 2 months ago (1 children)

And every service runs as root. This enables the CRL webserver to download /etc/shadow ...

[–] [email protected] 5 points 2 months ago

Or user sessions persist on the filesystem so a glitch on the captive portal’s web server allow you to get clear text username and password for currently connected vpn sessions …

[–] [email protected] 6 points 2 months ago

Yep. Closed source is for the software that no one would ever buy if they could read it.