Marcus Hutchins @malwaretech.com · May 7

I found a zero day in a security vendor's firewall software that allows you to remotely crash the entire system by sending it a single malicious packet. Since the firewall is responsible for inspecting traffic prior to the operating system handling it, no ports even need to be open for it to work.

353 likes 19 replies

?

Replies

Secretbatcave · May 7

I didn't know that fortigate ran on windows....

Simon W. Hall · May 7

"Ping of Death v2?" en.wikipedia.org/wiki/Ping_of...

Angela Trainor · May 7

That’s fascinating. I’m curious how you went about making this discovery. Did you personally write the malware or did you adapt a preexisting trojan attack of some sort?

SocPup · May 8

If a single packet can crash a firewall it is probably not a firewall issue, but different layer issue, like OS, network implementation or something else. Then again, have seen some weird "firewalls" out there where packets are parsed directly. But, probably isn't science 😂 when are you publishing?

Matt · May 7

Oh, great. New SYN-flood type of attacks, just reset their box? Hm, where can I try this PoC because I want to see if it hits my environment as demo'd.

Paolo Fabio Zaino ☮️🌍💻🎸🎮☕️🍩🍕 · May 8

Hopefully it's not a "vibe coded" firewall! 😆

SoonerMedic · May 7

Can’t have data exfil and encryptor deployment, if everything is in a perpetual boot cycle! 😂

Patrick Devaney · May 7

That's not ideal.

@werner58.bsky.social · May 8

Wow, that takes me back to high school. Nuke Nabber is still with us!

NOT e.g. Alice Roberts · May 7

What vendor?

Kazu Sato · May 7

Even when the firewall was supposed to filter that... Windows isn't innocent either, since isn't doing sanitization on input.

Spanky · May 8

Elyon113 · May 7

*Tosses a packet to your firewall

T

TexasCowboy · May 7

Not a surprised at all. Free Open Source Software is pervasive in vendor security products, including multiple versions of the same library module and literally thousands of people write and contribute - it's usually insecure as you might imagine.

Jmeyernj · May 7

big sigh

Afterimage 🇨🇦 · May 7

Ahh yes And then they blame you for breaking their system. Been there Done that Crashed an HPUX system trying to connect on port 23 on a security scan.

Travelling Will · May 7

Love the file name for the packet.

Name_Too_Long · May 7

Looks like ping of death is back on the menu

outlet :3 · May 7

Bruh