A firewall wake up call. [Research Saturday]
CyberWire Daily
N2K Networks, Inc.
4.8 • 1.1K Ratings
🗓️ 9 November 2024
⏱️ 23 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | You're listening to the Cyberwire Network, powered by N2K. |
| 0:09.7 | AI adoption is exploding, and security teams are under pressure to keep up. |
| 0:16.9 | That's why the industry is coming together at the Datasec AI conference, |
| 0:21.4 | the premier event for cybersecurity data and AI leaders, hosted by data security leader, |
| 0:27.4 | Saira. |
| 0:28.5 | Built for the industry, by the industry, this two-day conference is where real-world insights and bold solutions take center stage. |
| 0:36.6 | Datasek AI 25 is happening November 12th and 13th in Dallas. |
| 0:41.8 | There's no cost to attend. |
| 0:43.4 | Just bring your perspective and join the conversation. |
| 0:46.7 | Register now at Datasek AI 2025.com backslash cyberwire. |
| 0:52.7 | Thank you. dot com backslash cyberwire. Hello everyone and welcome to the CyberWire's research Saturday. |
| 1:07.3 | I'm Dave Bittner and this is our weekly conversation with researchers and analysts |
| 1:11.9 | tracking down the threats and vulnerabilities, solving some of the hard problems and protecting |
| 1:17.1 | ourselves in a rapidly evolving cyberspace. Thanks for joining us. |
| 1:27.1 | We're diving into this because we were interested in getting more familiar with the Sonic Wall Next Generation Firewall Platform, Sonic OS. |
| 1:35.7 | It's been the subject of a lot of vulnerabilities in the past, and we wanted to be prepared to be able to research in the platform, you know, whenever anything new came out. |
| 1:45.4 | That's John Williams, senior security engineer at Bishop Fox. |
| 1:49.8 | The research we're discussing today is titled Sonic Wall Firewalls are publicly exploitable. |
| 2:06.7 | And so in order to do that, I went back and looked through the history of all the different advisories that had been released, looking for things that were unauthenticated, had a |
| 2:12.3 | potential for remote code execution, and didn't have a known proof of concept. And the one bug that jumped out at me was this one from 2022, which met all those criteria. |
| 2:22.5 | So I figured it was a good research target and dove in to see if we could exploit it. |
| 2:27.3 | And we're pretty successful in the end. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

