This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Forget your Perimeter: From Phishing Email to Full VPN Compromise

Download resources

About this session

GoSecure researchers Julien Pineault and Jean-Frederic Gauron present four vulnerabilities they found in a Pulse Secure VPN appliance during a client assessment, and chain them into a realistic attack. They open by showing how to decrypt the appliance file system by editing the virtual machine's memory to swap the restricted console for a root shell, a technique adapted from Orange Tsai's earlier VPN research. They then detail two cross-site scripting flaws (one in a low-privilege bookmark page usable for cookie theft and persistence, one in the admin dashboard), a command-injection bug that yields remote code execution by writing shell code to a writable cache file, and an XML external entity flaw allowing file reads and internal port scans. Live videos demonstrate stealing a user cookie and gaining code execution through phishing. Much of the talk is a candid account of a frustrating disclosure process through HackerOne, where two findings were dismissed as duplicates, and a reflection on the contrast between penetration testing and bug bounty.

Like it or not, the perimeter has been a necessary line of defense to protect corporate networks from adversaries. Virtual Private Networks (VPNs) appliances are exposed on that perimeter in order to allow employees or trusted 3rd parties to access the internal network, a growing necessity in current times. But what if that appliance you trust is vulnerable and could be the very vector that leads attackers right in? This presentation summarizes an encounter during a penetration test with such an appliance. We will go over the technical details of two cross-site scripting (XSS), one XML eXternal Entity (XXE) and one command-injection vulnerabilities all affecting the latest Pulse Secure VPN product. We will then integrate them in a realistic attack scenario that demonstrate how an external attacker with only a little bit of OSINT can chain these vulnerabilities to pivot into the internal network from outside.

All the vulnerabilities discovered and discussed in this presentation were responsibly disclosed to the vendor and a 90-day window will have been respected by the time of the presentation. 

Key takeaways

  • Treat VPN appliances as part of your attack surface: a trusted perimeter device with unpatched XSS, command injection or XXE can be the exact vector that leads attackers into the internal network.
  • You can decrypt a locked appliance's file system by suspending the VM and editing its memory to swap the restricted console for a shell, giving root and cleartext source code.
  • Do not dismiss phishing-dependent bugs as low risk; in real engagements someone almost always clicks, so authenticated XSS and RCE remain highly exploitable.
  • Distinct vulnerabilities that share a code path still need separate fixes; a bug-bounty triage that merges them as duplicates can leave one silently unpatched.
  • Chain low-severity findings deliberately: an XXE used to read files can serve as debugging setup for a remote-code-execution exploit.

Speakers

Julien Pineault
Julien Pineault
Security analyst · GoSecure

Resources

Tags

More from GoSec 2020

Also from Jean-Frédéric Gauron

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.