Podcast Detail

SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10080.mp3

Podcast Logo
SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Thursday, September 3rd, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in Cloud
 Security. SonicWall users, be aware there is currently an
 active exploit available for a vulnerability that SonicWall
 just fixed this week. There are actually two
 vulnerabilities that are chained together for this
 particular exploit. The first one is, well, you may have
 guessed it, server-side request forgery yet again.
 Server-side request forgery is being used here to bypass
 authentication. So you essentially use the front-end
 web server here as a proxy to access an internal API. That
 internal API sees the request comes, well, from itself. So
 it doesn't really do any authentication access control
 on the request. The second part is that once you have
 authentication bypassed, you're able to execute
 arbitrary code using the second vulnerability. So two
 vulnerabilities that are being abused here together. And
 again, this is already exploited in the wild.
 Definitely something that you need to address quickly. It
 does affect the SMA-1000 series from SonicWall. And
 given that we do have so many of the server-side request
 forgery vulnerabilities coming up in recent months, well, I
 figure it just makes sense that I point you to a very
 comprehensive blog post was published by xclown.com. This
 blog post goes over many, many of the little nitty-gritty
 details when it comes to URL validation and the problems
 also with different implementations. So where
 different implementations may parse the same URL
 differently. Really interesting blog post if you
 are trying to validate URLs, particularly if you are trying
 to prevent server-side request forgery and highly recommend
 that you take a look at it. Also, if you're trying to
 exploit it, of course, this may give you some interesting
 ideas. And talking about vulnerabilities that keep
 showing up, well, the next story is also about a
 vulnerability or a type of vulnerability we have seen
 before. And that's the fact that your agents will actually
 trust what they find on the Internet. In this particular
 case, yet again, Git repositories. So in order to
 interact with a Git repository, your AI agent will
 often clone or download the content. Well, and as part of
 that, it often will refresh the index to check if there
 were any updates to the files. In order to speed up the index
 refresh, there is a Git option that will run a helper command
 whenever you're trying to refresh the index. This option
 is defined in your .git configuration files. And,
 well, you probably imagine it by now. You can, as an
 attacker, just specify any command here. And that command
 will be executed whenever the agent attempts to refresh the
 index. They tested multiple agents out of the eight. They
 found eight were vulnerable. Four have fixed this issue by
 now. But others are still vulnerable and still have to
 be treated with caution. Well, as I talked about before, you
 really have to be careful what files, what websites your
 agents are visiting as you're giving them tasks. Because,
 well, that could in some cases then lead to remote code
 execution. And Huntress published a blog post showing
 how threat actors are abusing Faronics. Faronics is one of
 those remote management tools. In this case, it's not
 something that the victim would have installed. Of
 course, that's also an option. But the attacker does install
 that tool to then, well, remote administer the host.
 Which means install additional software, share screens, and,
 well, do whatever attackers are doing. The goal, of
 course, here is that Faronics is a normal, valid software.
 And as such, often not detected by endpoint
 protection. It does not match any, like, malware signatures
 per se. But it's definitely software that you must keep an
 eye on. Similar to screen sharing software, like
 TeamViewer and such, which is legitimate software but often
 abused. Definitely make sure that nothing like this all of
 a sudden gets installed on your systems. And Huntress
 does provide some indicators of compromise here that you
 can use to check. Well, and that's it for today. So,
 thanks for listening. Thanks for liking. Thanks for
 subscribing and recommending this podcast. And talk to you
 again tomorrow. Bye.
 Bye. Bye. Bye. Bye. Bye. Bye.