Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Considering Cavium is in a bulk of all hardware appliances (networking/security) and it's related to chip firmware and many organizations are bad at updating software on hardware... My guess is that even though he's scanning for vulnerable services - that doesn't actually expose the true amount of servers vulnerable.

If you think about corporate networks that are doing SSL/TLS decrypt these boxes that are the corporate owned MitM will be vulnerable to this since the hardware is basically forward-proxying the users session. That would mean the connection between the appliance and the service would be vulnerable - something you can't scan for via something like the prober he mentions.

Very interesting indeed...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: