Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The Cavium thing is worrisome, because that's a part that might be on the BOM of a bunch of other products. Cavium makes network processors and TLS offload devices.


Considering Cavium is in a bulk of all hardware appliances (networking/security) and it's related to chip firmware and many organizations are bad at updating software on hardware... My guess is that even though he's scanning for vulnerable services - that doesn't actually expose the true amount of servers vulnerable.

If you think about corporate networks that are doing SSL/TLS decrypt these boxes that are the corporate owned MitM will be vulnerable to this since the hardware is basically forward-proxying the users session. That would mean the connection between the appliance and the service would be vulnerable - something you can't scan for via something like the prober he mentions.

Very interesting indeed...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: