Open cardosec

Case 251F6D · Network · L5 Expert

VPN Appliance Phones Home

Practise as: Incident drill · Interview

Live alertThe vendor integrity checker on your SSL VPN appliance reports unknown files, and flow logs show it connecting to a VPS at 04:10; a public auth-bypass exploit dropped two days ago.

Interview questionYou cannot run EDR on this box. How do you investigate, contain and recover?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Treat as edge-device compromise: no EDR, on-box logs may be tampered, so rely on vendor tooling, flow and external logs
  2. Preserve per vendor guidance (image, logs, integrity output) before reset; then isolate or cut user and admin portals
  3. Assume harvested secrets: reset VPN user creds, revoke sessions, rotate the appliance LDAP/AD bind account and its certs
  4. Scope the pivot: hunt connections from the appliance inside IP to DCs and servers, new accounts, since the exploit date
  5. Rebuild from known-good firmware then patch; patching alone may not evict implants, and integrity checkers can be evaded

If the interviewer pushes back

  • The integrity checker comes back clean after a reboot. Why is that not proof the device is clean?
  • What architecture changes reduce the blast radius of the next edge-device zero-day?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.