7
submitted 1 month ago* (last edited 1 month ago) by cron@feddit.org to c/cybersecuritymemes@lemmy.world

Fortinet, Palo, Checkpoint, Cisco, Sonicwall ... is there any big firewall vendor that didn't have any critical vulnerabilities last year?

top 10 comments
sorted by: hot top controversial new old
[-] M33@lemmy.sdf.org 3 points 1 month ago

Obsolete binaries not updated for years, hardcoded secrets… this is what you get in firewalls like any other piece of black box equipment.

[-] MajorHavoc@programming.dev 2 points 1 month ago

Yep. Closed source is for the software that no one would ever buy if they could read it.

[-] cron@feddit.org 2 points 1 month ago

And every service runs as root. This enables the CRL webserver to download /etc/shadow ...

[-] M33@lemmy.sdf.org 1 points 1 month ago

Or user sessions persist on the filesystem so a glitch on the captive portal’s web server allow you to get clear text username and password for currently connected vpn sessions …

[-] lennivelkant@discuss.tchncs.de 1 points 1 month ago

Security by obscurity may work in delaying exploits, but once someone breaks the obscurity, they have a headstart on exploiting it over those hoping to fix it.

[-] cron@feddit.org 1 points 1 month ago

Security by old software, or how I call it: the ivanti approach

[-] fruitycoder@sh.itjust.works 2 points 1 month ago

Did nftables or ebpf have any critical zero days last year?

[-] cron@feddit.org 4 points 1 month ago

AFAIK not. This meme is targeted at commercial firewall appliances, that often have VPN/IPS/authentication and many other features that are exploited regularly.

[-] kolorafa@lemmy.world 1 points 1 month ago
[-] cron@feddit.org 1 points 1 month ago

sounds correct

this post was submitted on 04 Jan 2025
7 points (100.0% liked)

Cybersecurity - Memes

1893 readers
1 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS