Will Dormann is on Mastodon

@wdormann.bsky.social

I play with vulnerabilities and exploits. While this site initially showed promise, I've grown tired with its lack of improvement. You'll find me @wdormann@infosec.exchange on Mastodon.

We all know that the Ivanti ICT cannot be trusted on a maybe-compromised device. Even the external ICT. But what about this recommended factory reset? That restores it to the state when you got it from the factory, right? Get real. Please avoid magical thinking, folks 🪄 (insert desire for GIFs here)

Only today did Google Nest send me a warning that my furnace started experiencing problems on January 9. Thanks for the tip, but guess what? I started noticing that there was trouble when... the house WAS COLD! Why was this information held back for a week and a half? 🤦‍♂️

Bild

CVE wonders: Apache created CVE-2023-49070 to capture: "Our OFBiz product has Apache XML-RPC, which is vulnerable to CVE-2019-17570". This seems... wrong? If every vendor created a new CVE to capture "Hey, we use library <foo> that already has a CVE", how can this possibly scale?

Let's use Ivanti VPN CVE-2024-21887 CVE-2023-46805 as an example of magical thinking. If you think your web server was compromised, would you use a remote web browser to confirm whether this is true? This is what the "external" ICT workflow does. Thoughts and prayers to customers.

The ICT in a nutshell
- Show me your admin page
- Here it is (trust me)
- Please run this ICT package
- OK, I will (trust me)
- I'm not compromised (trust me)Rickrolled external ICT resultsWe have seen evidence of threat actors attempting to manipulate Ivanti’s internal integrity checker (ICT). Out of an abundance of caution, we are recommending that all customers run the external ICT. We have added new functionality to the external ICT that will be incorporated into the internal ICT in the future.Shia LeBouf Magic

Meanwhile on the smoldering remains of the Twitter site: Elmo finds a way to make it better for the worst people on the planet. I also love how it says "subscribed", which I'm clearly not, and have had the account blocked for years.

Bild

It's so embarrassingly weird over at that other site. My hope is that BlueSky will get to the point where it's open to the public before Twitter explodes and/or the exodus actually happens. Otherwise, it'll just be a fun little experiment.

Tab for X (formerly Twitter) with 3 X's