🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 3 Min Lesezeit
0

Batfish marks Huawei VRP as unsupported — so I built a source-traceable IR for it

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

If you do network automation, you reach for fills.






Provenance is the whole point



vrp-ir parses a Huawei VRP/USG config into a typed model where every parsed value carries a SourceRef back to its file:line:




CODE
from vrp_ir import parse_file

cfg = parse_file("edge-fw.cfg")
ip = cfg.interfaces[0].ipv4[0]
print(ip.address.value, ip.prefix_length.value) # 10.10.10.1 24
print(ip.address.source) # edge-fw.cfg:11 <- provenance






When a value looks wrong, you jump straight to the line — you don't grep the raw config. That sounds small until you're reviewing a 4,000-line firewall dump and every claim in your report needs to be defensible.






From IR to a line-cited security audit



Provenance pays off the moment you turn the IR into findings. vrp-ir audit runs 13 security acceptance checks, and every finding cites the exact config line it's based on:




CODE
$ vrp-ir audit edge-fw.cfg
### FW-DEFAULT-DENY [CRITICAL] — default action denies unmatched traffic
Default action is 'permit': all traffic matching no rule is allowed.
Evidence:
- edge-fw.cfg:14 — default action permit




The checks cover the boring-but-deadly stuff: permit-any rules, a non-default permit default action, cleartext management (Telnet/HTTP), VTY accepting Telnet or missing an inbound ACL, weak SSH ciphers (CBC/3DES/DES), local AAA users with Telnet, address-sets that resolve to 0.0.0.0/0, and HRP consistency.



And because --strict exits non-zero on any failure, it drops straight into CI as an acceptance gate:




CODE
$ vrp-ir audit edge-fw.cfg --strict || echo "acceptance failed"




No more "the report says it's fine" with nothing to point at — each line of the report points at a line of the config.






Design choices





  • Zero-dependency core, Python 3.9+, pip install vrp-ir. Easy to embed.


  • Reuse, don't reinvent. It complements ntc-templates (show-command parsing), napalm (live collection) and Batfish (multi-vendor analysis) — it doesn't try to replace them.


  • No garbage facts. If a value can't be parsed cleanly, it's skipped rather than surfaced wrong. Provenance or nothing.






Where it's going — and how to help



It's v0.6 / alpha and moving fast. Next up: SNMP communities, NTP/Syslog presence, vsys, and a wider real-world test corpus. The best contributions are real, de-identified configs it parses wrong — those become the best issues. There are a handful of good first issues open right now (parsing SNMP/NTP/syslog with provenance) if you want a gentle on-ramp.



vrp-ir is Apache-2.0 and stays that way. It's the open core of AegisTwin, a Huawei security-acceptance workbench I'm building — but the parser and the audit are useful on their own today.



→ Repo + 30-second demo: https://github.com/zynovexllc/vrp-ir

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Batfish marks Huawei VRP as unsupported — so I built a source-traceable IR for it

Thematisch verwandte Begriffe: Batfish, marks, Huawei, unsupported · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...