Posts
4412
Following
737
Followers
1649
"I'm interested in all kinds of astronomy."
repeated
Edited 8 hours ago

The Palo Alto Networks firewall Master Key is p1a2l3o4a5l6t7o8 and it is well past time you changed it!

If you have never changed it, your LDAP service account password is sitting in your firewall config encrypted with a key the whole internet has known since 2016 [1]. So are your API keys, certificate private keys, RADIUS secrets and IPSec pre-shared keys.

And that config is on someone's laptop. In SharePoint. In a ticket you raised with Palo support three years ago.

Public tools [2] will decrypt anything encrypted with the default key. Any threat actor who gets one of those files gets your LDAP service account and walks straight off the firewall into your AD.

This is not theoretical.

Palo's own Unit 42 [3] documented attackers copying running-config.xml to a web-accessible path and retrieving it after exploiting CVE-2024-3400.

Fortinet has had two mass events on exactly this pattern: the Belsen Group dump of ~15,000 FortiGate configs and VPN credentials in January 2025 [4], and FortiBleed in June 2026, where configs from ~75,000 firewalls were cracked offline into working admin credentials [5].

You have always been able to change the Master Key. In my experience nobody ever does as it hasn't been without risk. If you forget to rotate the key before it expires then you risk bricking your firewall.

In PAN-OS 12.2.2, Palo Alto Networks have finally started forcing the issue. It enforces replacement of the default master key within a grace period of 60 days after which the firewall blocks all commits and HA synchronisation. This is a significant operational change and it is not in the release notes but is buried in the admin guide [6].

Three things to do in the next few weeks:

  1. Check your config backups are automated and actually working. You want a known-good backup before you touch the key.

  2. Change the Master Key. Do it on your schedule, not on Palo's.

  3. Rotate the secrets. Changing the key re-encrypts the secret on the box; every copy already out there is still decryptable with the default key.

For more depth see my research [7] and conference talk [8].

[1] @felix "Attacking Next-Generation Firewalls: Breaking PAN-OS", TROOPERS16 — https://troopers.de/media/filer_public/a5/4d/a54da07e-3780-4f83-b4ac-8c620666a60a/paloalto_troopers.pdf
[2] https://github.com/cybliminal/palo-secret-decryptor
[3] https://unit42.paloaltonetworks.com/cve-2024-3400/
[4] https://censys.com/blog/fortigate-config-leak-impact/
[5] https://www.picussecurity.com/resource/blog/fortibleed-inside-the-campaign-that-cracked-75000-fortinet-firewalls
[6] https://docs.paloaltonetworks.com/ngfw/administration/certificate-management/master-key-encryption/configure-master-key
[7] https://cybliminal.com/pdf/Panning_for_Gold.pdf
[8] https://www.youtube.com/watch?v=2PF4aSY1gVo

0
7
0
repeated

Frequently Asked Questions

1. what the fuck

2
29
0
[RSS] Stealing the Artifact - JFrog Artifactory Vulnerability

https://www.netspi.com/blog/technical-blog/red-teaming/stealing-the-artifact-jfrog-artifactory-vulnerability/

CVE-2026-42018, CVE-2026-69107
0
1
2
[RSS] Ruby 4.0 Universal RCE Deserialization Gadget Chain

https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain
0
1
2
[RSS] new tool release: zipmi

https://trouble.org/new-tool-release-zipmi/

"a pure-Python IPMI/BMC stack"
0
2
2
repeated

and here's our poc for postgres server RCE: https://github.com/v12-security/pocs/tree/main/postgresql/server

CVE-2026-14669. patched postgreSQL 18.6.

poc for client RCE 🔜
https://bird.makeup/users/v12sec/statuses/2073174525496459565

0
4
0
repeated

And right on schedule (after the Patch Tuesday release), we have ShieldBreak from Nightmare Eclipse. Which is reportedly an insufficient fix for RoguePlanet.

In my brief testing, Defender needs to be enabled for the exploit to work.

1
6
0
repeated

We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.

https://www.404media.co/we-tracked-a-shipment-of-rare-books-it-ended-at-an-amazon-ai-training-facility/

5
24
1
repeated

Dear EU, don't listen to , kill the cookie banner now!

4
11
0
repeated

Readeck 0.23.1 was released with some frontend fixes and improvements, as well as a fix for some OIDC providers.

https://readeck.org/en/blog/202608-readeck-23/

0
1
0
[RSS] From P-Code to GNN: extract binary code semantics

http://blog.quarkslab.com/from-p-code-to-gnn-extract-binary-code-semantics.html
0
0
0
This is a new low:

YouTube requires me to confirm my age if I *search* for "hair lbj" (I'm old enough if I search for this song, trust me).

Direct link to an uploaded version works.
0
0
3
repeated

I spent the past few days going down various fascinating rabbit holes using a nifty new service called Decryptads.com, which scrapes a metric ton of adtech data from websites and apps about who they allow to collect data and serve ads.

A search in DecryptAds for the hugely popular sports network espn.com, e.g. reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.

DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine.

A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

This service is a gold mine for security researchers, journalists and anyone interested in privacy, adtech, AI slop sites, residential proxies, malvertising, etc. Want to read more? Check out today's story:

https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/

12
32
0
random, probably from old tumblr
0
5
10
repeated

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/

0
1
0
Little human eating ice cream with grandpa:

"Is this delicious or cold?"

#Spotted in Budapest District VIII.
0
0
3
repeated

During yesterday's solar eclipse, Spanish Olympic skateboarder Danny Leon performed a jump, timing the trick with the moon passing in front of the sun. Leon shared the epic stunt on his social media accounts and called it ‘the move of his life.’

0
3
0
@alex Excellent read, thank you!

"Was the warning broken? Was our theory wrong? Was the true bug still lurking in the darkness?" - I feel this so much!
0
0
1
Show older