You are on page 1of 3

STEALIEN Presents

STEALIENEWS
Week -2 November 15th 2021 Issue #0211

Back-to-Back PlayStation 5 Cyberattackers stole PS5 root keys and exploited

Hacks Hit on the Same Day


the kernel, revealing rampant insecurity in gaming
devices.

BY: STEALIEN INDONESIA In a subsequent tweet, the group claimed that it “Hackers may have just made
“…got all (symmetric) ps5 root keys.” some big strides towards
FlailOverflow wrote,
possibly jailbreaking the
“They can all be obtained from PlayStation 5 over the
A pair of PlayStation 5 breaches shows the
consoles don’t have protection from attackers software — including per-console weekend,”
taking over its most basic functions. root key, if you look hard enough!” Schneier wrote about the breaches.
Both exploits were posted on Twitter on Nov. 7 The message is practically a dare for other
without disclosure to Sony or specifics, but they would-be hackers to try to access decrypted “Decrypted firmware which is
nonetheless signal potential security problems to firmware files for themselves. possible through
come for the gaming giant. FailOverFlow’s keys, would
PS5 Kernel Exploit
FailOverFlow, which has already earned a potentially allow for hackers to
reputation as a prolific PlayStation jailbreaker The second hack was also posted on Twitter on further reverse-engineer the PS5
group, posted a Nov. 7 tweet which appeared to Nov. 7 by Google security engineer Andy software and potentially develop
contain the PS5 firmware symmetric root keys: Nguyen, who is also known widely in hacker the sorts of hacks that allowed
circles as TheFlow. He was apparently able to
access the PlayStation 5 “Debug Settings” for things like installing Linux,
menu, indicating he has a PS5 kernel exploit. emulators or even pirated games
on past Sony consoles.”
Wolo, which first reported on both breaches,
pointed out this menu is typically only Schneier added that he doesn’t think
on testkit devices and allows quality assurance a hack-proof computer system will ever
and development teams to install package files be a reality.
on the Sony PlayStation 5.

“But it can be enabled on retail consoles by


“Especially when the system is
patching some flags, located at specific physically in the hands of the
addresses in the firmware at Runtime,” hackers,” Schneier said. “The
according to Wololo’s the Guardian. Sony Playstation 5 is the latest
Is Securing the PS5 Even Possible? example.”

Both breaches put threat actors well on their


way to installing pirated games, running
emulators and more, according to public-
interest technologist Bruce Schneier.

Page 1
Monday November 15, 2021 STEALIENEWS Issue #0211

Few Technical Details, Many Affected


Products

While Citrix didn’t release technical details on


the latest bugs, VulnDB noted on
Wednesday that for CVE-2021-22955, “the
exploitability is told to be difficult. The attack
can only be initiated within the local network.
The exploitation doesn’t require any form of
authentication.” It assigned a severity score of
5.1 out of 10 to the bug, despite Citrix’ internal
rating of “critical.”

The site also reported that exploits are


calculated to be worth up to $5,000, and noted
that “manipulation with an unknown input
leads to a denial of service vulnerability…This

Critical Citrix DDoS Bug Shuts


is going to have an impact on availability.”

The vendor said the vulnerabilities affect the

Down Network, Cloud App


following supported versions:

Citrix ADC and Citrix Gateway (CVE-2021-

Access
22955 and CVE-2021-22956):

• Citrix ADC and Citrix Gateway 13.0


before 13.0-83.27
The distributed computing vendor patched the flaw, Tracked as CVE-2021-22956, the second
affecting Citrix ADC and Gateway, along with flaw allows temporary disruption of: a
another flaw impacting availability for SD-WAN • Citrix ADC and Citrix Gateway 12.1
appliances. device’s management GUI; the Nitro API for before 12.1-63.22
configuring and monitoring NetScaler
BY: STEALIEN INDONESIA appliances programmatically; and remote
procedure call (RPC) communication, which
• Citrix ADC and NetScaler Gateway
11.1 before 11.1-65.23
is what essentially enables distributed
computing in Citrix settings. • Citrix ADC 12.1-FIPS before 12.1-
A critical security bug in the Citrix 55.257
In terms of the impact of exploitation, all
Application Delivery Controller (ADC) and three products are widely deployed globally, Citrix SD-WAN WANOP Edition (CVE-
Citrix Gateway could allow cyberattackers with Gateway and ADC alone installed in at 2021-22956):
to crash entire corporate networks without least 80,000 companies in 158 countries as of
needing to authenticate. early 2020, according to an assessment from • Models 4000-WO, 4100-WO, 5000-
Positive Technologies at the time. WO and 5100-WO
The two affected Citrix products (formerly
the NetScaler ADC and Gateway) are used Disruption to any of the appliances could • Version 11.4 before 11.4.2
for application-aware traffic management prevent remote and branch access to
and secure remote access, respectively. The corporate resources and general blocking of • Version 10.2 before 10.2.9c
federated working specialist pushed out a cloud and virtual assets and apps.
security patch on Tuesday for the • The WANOP feature of SD-WAN
vulnerability, tracked as CVE-2021-22955, All of this makes them an attractive target for Premium Edition is not impacted.
which allows unauthenticated denial of cybercriminals, and indeed, the Citrix ADC
service (DoS), due to uncontrolled resource and Gateway in particular are no spring In the case of the first Citrix ADC and
consumption, according to the advisory. chickens when it comes to the critical Gateway bug, appliances must be configured
vulnerability scene. as a VPN or AAA virtual server in order to be
Citrix also addressed a lower-severity bug vulnerable.
that is likewise due to uncontrolled resource In the summer of 2020, multiple
consumption. It impacts both previous vulnerabilities were discovered that would In the case of the second bug, appliances must
products, as well as the Citrix SD-WAN allow code injection, information disclosure have access to NSIP or SNIP with
WANOP Edition appliance. The latter and denial of service, with many exploitable management interface access.
provides optimization for Citrix SD-WAN by an unauthenticated, remote attacker. And,
deployments, which enable secure in December of 2019, a critical RCE bug was Customers using Citrix-managed cloud
connectivity and seamless access to virtual, disclosed as a zero-day that took the vendor services are unaffected.
cloud and software-as-a-service (SaaS) apps weeks to patch.
across enterprise and branch locations.

IT SECURITY TIPS What makes social engineering so dangerous is • Do not open any emails from untrusted
that it preys on human error, much more of a sources. Sound advice under any
wild card—and much harder to track—than circumstances.
taking advantage of vulnerabilities in software
Social engineering refers to a broad
and operating systems. • If an offer seems too good to be true, assume
spectrum of malicious activities using
it is.
psychological manipulation to trick users Social Engineering bad guys try to get at users
into giving away sensitive information. through human psychology and preying on • Lock your laptop whenever you are away
Perpetrators are particularly patient, waiting curiosity. It’s important to go into all cyber- from your workstation.
in the weeds, collecting data and situations with your eyes wide open because
background information on their intended only the users and employees can counter these • Make sure your antivirus/malware software
victims. attacks. is up to date.
Then they gain the victim’s trust and Here are several tips employees can keep in • Be vigilant about cyber security.
provide seemingly harmless reasons for mind to protect themselves (and your
their victims to give up sensitive business):
information.

Page 2
Monday November 15, 2021 STEALIENEWS Issue #0211

Indonesia religious council says


crypto trading forbidden for Visualization of world’s largest capital market of

Muslims
cryptocurrency, Bitcoin

BY STEALIEN INDONESIA BIG NUMBER Crypto transactions amounted to 370 trillion


rupiah ($26 billion) in the first five months of
232.3 million. That’s the approximate number the year in Indonesia, still a fraction of the
of Muslims in Indonesia, where nearly nine in global market at around $3 trillion.
ten of its population is Muslim, according to
The Indonesian Ulema Council, a top body of the U.S. Department of State. Indonesia has the The stance of Indonesia’s religious leaders
Islamic scholars, said Thursday world’s fourth-largest population and the 10th may diverge from their counterparts in other
cryptocurrency as a means of payment and a largest economy by purchasing power parity, Muslim-majority countries. The United Arab
commodity to trade is unlawful for Muslims in according to the World Bank. Emirates have allowed crypto trading in
that country that has the world’s largest Dubai’s free zone, while Bahrain have backed
Muslim population, according to multiple CONTRA crypto assets since 2019.
reports, a ruling that could affect Muslims’
financial decisions in that country though the Other predominantly Muslim countries The Ulema Council advises the country’s
council does not have legal powers. support cryptocurrency. In September, the finance ministry and central bank on Islamic
United Arab Emirates’ financial regulators finance issues. It comprises many Indonesian
According to Fortune, the council advises agreed to offer the trading of digital tokens in Muslim groups including Nahdlatul Ulama
Indonesia's government, including its finance Dubai’s free zone. In 2019, Bahrain became (NU), Muhammadiyah, and smaller groups
ministry, on finance and banking matters for the first Arab country to issue rules on crypto such as Syarikat Islam, Perti, Al Washliyah,
Muslims—around 87% of Indonesians follow and has since backed crypto. Mathla’ul Anwar, GUPPI, PTDI, DMI, and Al
Islam. Ittihadiyyah.
KEY BACKGROUND
The council’s head of religious decrees, The MUI decree is not legally binding and does
Asrorun Niam Sholeh, said crypto has Though the council’s decree has no legal not mean cryptocurrency is banned in
elements of uncertainty and harm, which authority, it could affect Muslims’ decisions Indonesia. However, it could deter Muslims
forbids it as a payment option under Sharia on spending and investing their money. The from investing and local institutions from
law, Reuters reports. council’s presence in Indonesia’s financial issuing or providing services in crypto assets.
sector has increased after the passage of a law
Asrorun added the use of digital tokens as a on Sharia Banking. Under that law, Indonesian In October, a provincial branch of one of the
commodity to trade is also forbidden, citing financial institutions are mandated to have a largest Islamic organizations in Indonesia,
their lack of a clear value and physical division that abides by Islamic law, according Nahdlatul Ulama, similarly declared
structure. to the East Asia Forum. cryptocurrency haram under religious law.
Crypto is traded and invested in Indonesia’s While the decision from MUI doesn’t mean all However, the Indonesian government has
commodities and futures market. cryptocurrency trading will be stopped in indicated that the country will not impose an
Indonesia, the decree could deter Muslims outright ban on cryptocurrency as China did.
Asrorun left room for change, saying the from investing in the assets and make local Crypto assets are allowed to trade alongside
council could approve cryptocurrency if institutions reconsider issuing crypto assets. commodity futures in Indonesia but cannot be
modifications are made to comply with Sharia Bank Indonesia has been mulling a central used as a currency. Meanwhile, the
law, according to Bloomberg. bank digital currency, with no decision government is pushing to set up a crypto
announced as yet. exchange by the end of the year and Bank
Total crypto transactions in Indonesia totaled Indonesia has been exploring a central bank
370 trillion rupiah, or $25.96 billion, between digital currency (CBDC).
January and May this year, according to
Indonesia’s trade ministry.

Page 3

You might also like