Author: Black Hat - Bewertung: 1x - Views:29
Palo Alto Networks' GlobalProtect is a widely adopted remote access solution used by major organisations worldwide — but how robust is it?
Is it designed following secure development principles? Is it possible that this highly-privileged agent, typically installed on all user endpoints, could actually be a source of vulnerability?
In this talk, I will introduce and discuss the research that led to the discovery of several security vulnerabilities that could be used to bypass the VPN or escalate privileges on MacOS and Linux endpoints with GlobalProtect installed.
As well as providing technical details and practical demonstration of the vulnerabilities, I'll provide an overview of how the GlobalProtect client works and consider its design from the security engineer's perspective. I'll explore fundamental design decisions whose overlooked risks directly contributed to the discovered vulnerabilities.
By:
Alex Bourla | Security Engineer and Researcher,
Graham Brereton | Senior Software Engineer, Form3
Presentation Materials Available at:
https://blackhat.com/us-25/briefings/schedule/?#turning-the-tables-on-globalprotect-use-and-abuse-of-palo-altos-remote-access-solution-46051
SOCIAL SHARE CARD GENERATOR