Here are some detection ideas for ManageEngine RCE CVE-2022-47966🧵:
1. According to the report, Java's RuntimeExec() executes the arbitrary command.
2. A quick search on Google shows that Java runs the command in a separate process. 1/2
#ThreatHunting
https://t.co/YRtxyn98V8
The best part of being a Leader is seeing one of my teammates accomplish a major goal they worked very hard to achieve. Even if that means leaving my team.
@cyb3rops@zero_B_S Hope this weekend narrows down affected services and conditions more precisely, including java versions.
In the meantime, for a little break for everyone working hard to mitigate and respond to this:
@Bowflexin91 I have only read pieces of his work. Some aspects of his ideas have merit, but his hostility towards mainstream science, and rejection of data that doesn't fit his own personal narrative -- is just a hard "no" for me.
After 2 episodes, I can say that Grahy Hancock seems like a good guy and I would love a chance to share some points with him at the pub. He is wrong ona ton of things but interesting thoughts.