5 ms·
> Can this vulnerability be exploited remotely? > Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
by 0x0000000 5y ago
> Can this vulnerability be exploited remotely?
> Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
- Arnavion 5y agoI would hope nobody's opening up the admin interface to the internet. It's certainly not the default. The pfSense / OPNsense codebase is not written to be secure against malicious users in general, even unauthenticated ones that can't get past the login screen. For example I'm pretty sure php-fpm does nothing to prevent slow-loris. (The admin interface listens on all network interfaces, including all WAN interfaces. However the default firewall rules black-hole all incoming traffic on the WAN interfaces.)
- vladvasiliu 5y ago> (The admin interface listens on all network interfaces, including all WAN interfaces. However the default firewall rules black-hole all incoming traffic on the WAN interfaces.) Also, at least in OPNsense, for some reason, not all interfaces get an IP in the DNS. So if you want to access the admin interface via a name with a certificate, it may not always work if you selectively enable the listening interfaces. I've had this happened a week ago, where the DNS name wouldn't resolve to the internal interface's IP for some reason... I would only get the WAN interface and some other restricted one I have.
- Arnavion 5y agoChange the Unbound settings to only listen on LAN interfaces, or even just one specific LAN interface. Eg I have four LAN interfaces but have Unbound configured to only listen on LAN1, so my router FQDN only resolves to the IPs of LAN1.
- pelasaco 5y agoI think the scenario isn't people hitting it through internet, but some attack chain involving, for instance a clickjacking, XSRF, XSS,etc in another website that try to access the UI in case the admin is authenticated in the firewall, visits the malicious website.
- suifbwish 5y agoI have never been able to figure out the intent of random slow loris attacks I’ve seen and mitigated on small networks I’ve worked on. It’s just random IPs connecting to the webserver for no reason other than to jam it. It’s not even a competition thing it’s like having a super soaker full of superglue and just spraying it up in the air blindfolded.
- dogecoinbase 5y agoNot great, but also a bit it-rather-involved-being-on-the-other-side-of-this-airtight-hatchway.
- donmcronald 5y ago> This vulnerability can be exploited by a remote authenticated privileged user via the Internet. I don’t get it. If you’re authenticated as a privileged user, don’t you have access anyway?
- dspillett 5y agoWhen holes like this are exploited it is in combination with other flaws like another app having an XSS flaw which allows a rogue script to make arbitrary connections. If you happen to have an active login session on the admin interface, that script could use the hole to make changes unbeknownst to you. Also in a situation where you have admins with different levels of access, exploits like this could allow an individual low on gruntles to create a privilege escalation situation and gain access to features they should not. So a low probability of exploit due to the mitigating factor, but a high potential for damage if an exploit is attempted and succeeds.