解密和重放 GlobalProtect VPN Cookie
Common Information
Type Value
UUID 26f92ba2-7d4b-4574-88f2-0e79cf960ed7
Fingerprint 1a86e31d189c061f
Analysis status DONE
Considered CTI value 2
Text language
Published June 20, 2024, midnight
Added to db Sept. 13, 2024, 8:48 a.m.
Last updated Nov. 17, 2024, 7:44 p.m.
Headline 解密和重放 GlobalProtect VPN Cookie
Title 解密和重放 GlobalProtect VPN Cookie
Detected Hints/Tags/Attributes 25/1/34
Source URLs
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 483 CN-SEC 中文网 https://cn-sec.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 3
cve-2019-1573
Details Domain 172
www.crowdstrike.com
Details Domain 4
vpn.example.com
Details Domain 3
hipreport.sh
Details Domain 2
custom-hips-profile.sh
Details Domain 4127
github.com
Details Domain 1
www.infradead.org
Details Domain 434
medium.com
Details File 1
这些.dat
Details File 50
hashlib.md5
Details File 1
hippolicy.dat
Details File 1
hip_am_report_v4.dat
Details File 1
hip_bc_report_v4.dat
Details File 1
hip_de_report_v4.dat
Details File 1
hip_dlp_report_v4.dat
Details File 1
hip_fw_report_v4.dat
Details File 1
pangps.log
Details File 1
pangphip.log
Details File 384
www.inf
Details File 1
globalprotect.html
Details Github username 9
openssl
Details Github username 1
halilugur
Details Github username 1
rotarydrone
Details md5 1
01000000D08C9DDF0115D1118C7A00C0
Details md5 1
c41006bcdbef6683b2e7387ea9487a77
Details sha1 1
16e7da091c67e072b6927fcbf8637824bfd13f83
Details Url 1
https://github.com/openssl/openssl/blob/16e7da091c67e072b6927fcbf8637824bfd13f83/crypto/evp/evpenc.c?source=postpage
Details Url 1
https://www.crowdstrike.com/blog/exploiting-escalation-of-privileges-via-globalprotect-part-1
Details Url 1
https://vpn.example.com
Details Url 1
https://github.com/halilugur/openconnect/blob/master/hipreport.sh?source=post_page
Details Url 1
https://github.com/rotarydrone/globalunprotect
Details Url 1
https://www.riskinsight-wavestone.com/en/2023/01/bypassing-host-security-checks-on-a-modern-vpn-solution
Details Url 1
https://www.infradead.org/openconnect/globalprotect.html
Details Url 1
https://medium.com/cyesec/no-portals-needed-79995d8f7e62