| ▲ | Nextgrid 5 days ago | |||||||
A firewall blocking outgoing connections (except those whitelisted through the proxy) would’ve likely prevented the download of the malware (as it’s usually done by using the RCE to call a curl/wget command rather than uploading the binary through the RCE) and/or its connection to the mining server. | ||||||||
| ▲ | denkmoon 5 days ago | parent | next [-] | |||||||
How many people do proper egress filtering though, even when running a firewall | ||||||||
| ▲ | drnick1 4 days ago | parent | prev [-] | |||||||
In practice, this is basically impossible to implement. As a user behind a firewall you normally expect to be able to open connections with any remote host. | ||||||||
| ||||||||