<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New RCE on GlobalProtect if you didnt change the master key in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572899#M115252</link>
    <description>&lt;P&gt;And if you have changed master key then don't forget to update it before it expires otherwise you need to reset your firewall to factory default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"You must configure a new master key before the current key expires. If the master key expires, the firewall or Panorama automatically reboots in Maintenance mode. You must then Reset the Firewall to Factory Default Settings."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/certificate-management/configure-the-master-key" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/certificate-management/configure-the-master-key&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 19:22:51 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2024-01-12T19:22:51Z</dc:date>
    <item>
      <title>New RCE on GlobalProtect if you didnt change the master key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/510683#M106246</link>
      <description>&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class="" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello All,&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I saw the below on twitter...&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="" dir="auto" lang="en" data-testid="tweetText"&gt;&amp;nbsp;
&lt;DIV id="id__aqcmba5pktc" class="" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I wrote a tool to check master key configuration on palo alto firewalls and so far I haven't run into any instances of people actually changing the master key from p1a2l3o4a5l6t7o8&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class=""&gt;
&lt;DIV id="id__uzystzbk8ie" class="" aria-labelledby="id__b1z0w7she49 id__1wsc8q1jrc4"&gt;
&lt;DIV id="id__1wsc8q1jrc4" class="" aria-labelledby="id__21vjx3gtuz4 id__wreki4s381s" data-testid="card.wrapper"&gt;
&lt;DIV id="id__21vjx3gtuz4" class="" aria-hidden="true" data-testid="card.layoutLarge.media"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;
&lt;DIV class=""&gt;
&lt;DIV class="" aria-label=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1659529373594.png"&gt;&lt;img /&gt;&lt;/span&gt;&amp;nbsp;
&lt;DIV id="id__wreki4s381s" class=""&gt;
&lt;DIV class="" data-testid="card.layoutLarge.detail"&gt;
&lt;DIV class="" dir="auto"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;gist.github.com&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="" dir="auto"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;check if a PAN firewall is using the default master key when globalprotect is enabled&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="" dir="auto"&gt;&lt;SPAN class=""&gt;check if a PAN firewall is using the default master key when globalprotect is enabled - checkmk.py&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1659529373594.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42755i865F0599DCA8E3B7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1659529373594.png" alt="OtakarKlier_0-1659529373594.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 03 Aug 2022 12:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/510683#M106246</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-03T12:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: New RCE on GlobalProtect if you didnt change the master key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/510751#M106255</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for sharing this.&lt;/P&gt;
&lt;P&gt;Adding the direct link from github:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://gist.github.com/rqu1/6175cb2972291fc9ac96ef18f72b792c" target="_blank"&gt;https://gist.github.com/rqu1/6175cb2972291fc9ac96ef18f72b792c&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 04 Aug 2022 09:03:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/510751#M106255</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-08-04T09:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: New RCE on GlobalProtect if you didnt change the master key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/511751#M106365</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Also changing the master key does not require a reboot so it can be done at anytime. Just remember to add it to your password manager, if lost you'll need a factory reset the device :(.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 17:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/511751#M106365</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-12T17:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: New RCE on GlobalProtect if you didnt change the master key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572586#M115213</link>
      <description>&lt;P&gt;This is old but got bubbled back up for me. Did we find out if this was the master key?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, do we know if any PAN-OS update change the master key?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 17:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572586#M115213</guid>
      <dc:creator>Usama-Ahmed</dc:creator>
      <dc:date>2024-01-10T17:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: New RCE on GlobalProtect if you didnt change the master key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572886#M115250</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You must change the master key manually. Also make sure to back it up.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 17:52:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572886#M115250</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-01-12T17:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: New RCE on GlobalProtect if you didnt change the master key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572899#M115252</link>
      <description>&lt;P&gt;And if you have changed master key then don't forget to update it before it expires otherwise you need to reset your firewall to factory default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"You must configure a new master key before the current key expires. If the master key expires, the firewall or Panorama automatically reboots in Maintenance mode. You must then Reset the Firewall to Factory Default Settings."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/certificate-management/configure-the-master-key" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/certificate-management/configure-the-master-key&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 19:22:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-rce-on-globalprotect-if-you-didnt-change-the-master-key/m-p/572899#M115252</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-01-12T19:22:51Z</dc:date>
    </item>
  </channel>
</rss>

