ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Bad one: SonicWALL Remote Management Vulnerability

    IT Discussion
    7
    17
    1.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PhlipElderP
      PhlipElder
      last edited by

      2019-07-19 Twitter - SonicWALL Advisory.PNG

      Their site was offline most of this morning. It seems to be back now.

      Rule #1: Never, ever, have a device connected to the Internet in an unrestricted manner for any kind of management. Never.
      Rule #2: Update it. Always. Pay the fee if need-be, but make sure it's up to date.

      The number of iDRAC/iLO/RMM horror stories heard around here as a result of being plugged directly into the Internet are sadly more numerous than they should be.

      PhlipElderP 1 Reply Last reply Reply Quote 3
      • PhlipElderP
        PhlipElder @PhlipElder
        last edited by

        @PhlipElder said in Bad one: SonicWALL Remote Management Vulnerability:

        2019-07-19 Twitter - SonicWALL Advisory.PNG

        Their site was offline most of this morning. It seems to be back now.

        Rule #1: Never, ever, have a device connected to the Internet in an unrestricted manner for any kind of management. Never.
        Rule #2: Update it. Always. Pay the fee if need-be, but make sure it's up to date.

        The number of iDRAC/iLO/RMM horror stories heard around here as a result of being plugged directly into the Internet are sadly more numerous than they should be.

        Did a blog post with a How-To for disabling: https://blog.mpecsinc.com/2019/07/19/important-sonicwall-vulnerability-patch-for-remote-management/

        DustinB3403D 1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403 @PhlipElder
          last edited by

          @PhlipElder Is the blog post 3 steps?

          1. unplug sonicwall
          2. open window
          3. throw sonicwall out open window

          ?

          PhlipElderP 1 Reply Last reply Reply Quote 1
          • PhlipElderP
            PhlipElder @DustinB3403
            last edited by

            @DustinB3403 said in Bad one: SonicWALL Remote Management Vulnerability:

            @PhlipElder Is the blog post 3 steps?

            1. unplug sonicwall
            2. open window
            3. throw sonicwall out open window

            ?

            I don't subscribe to that religion. 😉

            1 Reply Last reply Reply Quote 0
            • wrx7mW
              wrx7m
              last edited by

              WTF? People NAT their iDracs?

              DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403 @wrx7m
                last edited by

                @wrx7m said in Bad one: SonicWALL Remote Management Vulnerability:

                WTF? People NAT their iDracs?

                Some people...

                notverypunnyN 1 Reply Last reply Reply Quote 1
                • notverypunnyN
                  notverypunny @DustinB3403
                  last edited by

                  @DustinB3403 said in Bad one: SonicWALL Remote Management Vulnerability:

                  @wrx7m said in Bad one: SonicWALL Remote Management Vulnerability:

                  WTF? People NAT their iDracs?

                  Some people...

                  Probably the same people that put ketchup on a perfectly good steak..... psychopaths the whole lot of them

                  1 Reply Last reply Reply Quote 3
                  • iroalI
                    iroal
                    last edited by iroal

                    4 years ago I changed SonicWall for Pfsense.

                    One of the best changes I've ever done.

                    scottalanmillerS 1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller @iroal
                      last edited by

                      @iroal said in Bad one: SonicWALL Remote Management Vulnerability:

                      4 years ago I changed SonicWall for Pfsense.

                      One of the best changes I've ever done.

                      We've been replacing pfSenses with UBNT, also a nice move 🙂

                      iroalI 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @wrx7m
                        last edited by

                        @wrx7m said in Bad one: SonicWALL Remote Management Vulnerability:

                        WTF? People NAT their iDracs?

                        As opposed to what? Having a disconnected management LAN and only jump boxes to get to them?

                        notverypunnyN 1 Reply Last reply Reply Quote 0
                        • notverypunnyN
                          notverypunny @scottalanmiller
                          last edited by

                          @scottalanmiller said in Bad one: SonicWALL Remote Management Vulnerability:

                          @wrx7m said in Bad one: SonicWALL Remote Management Vulnerability:

                          WTF? People NAT their iDracs?

                          As opposed to what? Having a disconnected management LAN and only jump boxes to get to them?

                          I think he was referring to inbound NAT / port forwarding from the internet as opposed to LAN only access

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @notverypunny
                            last edited by

                            @notverypunny said in Bad one: SonicWALL Remote Management Vulnerability:

                            @scottalanmiller said in Bad one: SonicWALL Remote Management Vulnerability:

                            @wrx7m said in Bad one: SonicWALL Remote Management Vulnerability:

                            WTF? People NAT their iDracs?

                            As opposed to what? Having a disconnected management LAN and only jump boxes to get to them?

                            I think he was referring to inbound NAT / port forwarding from the internet as opposed to LAN only access

                            Oh, yeah PORT FORWARDING to an iDRAC would be pretty "not recommended." But behind a NAT firewall would just allow them to reach out and update, and no one to reach in by default.

                            1 Reply Last reply Reply Quote 0
                            • iroalI
                              iroal @scottalanmiller
                              last edited by

                              @scottalanmiller said in Bad one: SonicWALL Remote Management Vulnerability:

                              UBNT

                              For what reason? Are there any problem with Pfsense ?

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @iroal
                                last edited by

                                @iroal said in Bad one: SonicWALL Remote Management Vulnerability:

                                @scottalanmiller said in Bad one: SonicWALL Remote Management Vulnerability:

                                UBNT

                                For what reason? Are there any problem with Pfsense ?

                                Not problems, pfSense is a good product. The biggest "problem" is the lack of vertical integration with hardware. With the UBNT we get software custom made for the specific hardware, and support. So we don't have to do our own installs, and don't need random third party software. It's one, inclusive package that is well known and tested both in the field and by the vendor. pfSense is software only and as a software firewall would be at the top of my list. But we deploy hardware and the benefits are the lower cost, better supported hardware with massive supply chain are pretty impossible to beat.

                                And the central monitoring features of UBNT carry a lot of value. We get centralized visibility.

                                iroalI 1 Reply Last reply Reply Quote 1
                                • iroalI
                                  iroal @scottalanmiller
                                  last edited by

                                  @scottalanmiller

                                  @scottalanmiller said in Bad one: SonicWALL Remote Management Vulnerability:

                                  @iroal said in Bad one: SonicWALL Remote Management Vulnerability:

                                  @scottalanmiller said in Bad one: SonicWALL Remote Management Vulnerability:

                                  UBNT

                                  For what reason? Are there any problem with Pfsense ?

                                  Not problems, pfSense is a good product. The biggest "problem" is the lack of vertical integration with hardware. With the UBNT we get software custom made for the specific hardware, and support. So we don't have to do our own installs, and don't need random third party software. It's one, inclusive package that is well known and tested both in the field and by the vendor. pfSense is software only and as a software firewall would be at the top of my list. But we deploy hardware and the benefits are the lower cost, better supported hardware with massive supply chain are pretty impossible to beat.

                                  And the central monitoring features of UBNT carry a lot of value. We get centralized visibility.

                                  Thanks for your opinion, I always learn of them.

                                  1 Reply Last reply Reply Quote 1
                                  • dafyreD
                                    dafyre
                                    last edited by

                                    PFSense has a newer fork now as well, known as OPNSense (https://opnsense.org/)

                                    More modern UI and such, decent packages available if you need extra stuff, but as far as routing and a firewall, it's pretty excellent!

                                    scottalanmillerS 1 Reply Last reply Reply Quote 2
                                    • scottalanmillerS
                                      scottalanmiller @dafyre
                                      last edited by

                                      @dafyre said in Bad one: SonicWALL Remote Management Vulnerability:

                                      PFSense has a newer fork now as well, known as OPNSense (https://opnsense.org/)

                                      More modern UI and such, decent packages available if you need extra stuff, but as far as routing and a firewall, it's pretty excellent!

                                      Both have a third party UTM add on option, too.

                                      1 Reply Last reply Reply Quote 0
                                      • 1 / 1
                                      • First post
                                        Last post