Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vmware vRealize network insight RCE CVE 2023-20887 #384

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

secureness
Copy link
Contributor

@secureness secureness commented Jan 29, 2024

Related to this issue.

I moved the setup guidance to here

@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Feb 1, 2024
@secureness
Copy link
Contributor Author

secureness commented Jun 25, 2024

@leonardo-doyensec I'm sorry if I should not ping you since this is a really important product I'd like to ask you to check this plugin sooner.
it seems that setting up a VCenter in a local computer without any physical server can be interesting and hard :)
I already used this complete tutorial to set up a home lab on a VMware workstation:
https://www.youtube.com/watch?v=ivTDffsFTHw&list=PLiWivaJb025ZSNxervevLYscEBCkCYuQP

it was a good experience for me, I believe you already know this though.

it would be great if I could get feedback on this ASAP.

@ikkisoft
Copy link
Collaborator

Hi @secureness, thank you for your contribution! Can you please submit a testbed for this detector in the https://github.com/google/security-testbeds repo?

@secureness
Copy link
Contributor Author

secureness commented Feb 12, 2025

hi @ikkisoft
I created the testbed. I also have the vRealize installation OVA files and bundle file and I uploaded it to my server. this is because Broadcom doesn't let to download these files easily( at least with personal email registration) anymore.
It would be great if someone downloaded the files as soon as possible(17GB).

@ikkisoft
Copy link
Collaborator

@secureness Thanks for the update, however we need more detailed how-to instructions so that anyone can download the appropriate software/keys and verify the correct functionality of the plugin. Also, it's not sufficient to reference a Youtube video - instead please summarize the minimal number of steps required for a proper setup.

For proprietary software (such as vRealize), we cannot host a copy; instead, the user would need to follow your step-by-step instructions in order to download the target software and setup the appropriate keys / configuration. Thanks!

cc: @leonardo-doyensec

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants