Skip to main content
zeromahesh
New Member
February 6, 2021
Question

Fortinet IPS does not block Joomla!.Core.Account.Creation.Privilege.Escalation Exploit

  • February 6, 2021
  • 1 reply
  • 8777 views

Dear All,

 

I have deployed Fortigate VM in AWS and all the licenses are active except Fortiguard. My issue is when I do a exploit to Joomla 3.4.4 instance placed behind the Fortigate VM through a Security Policy which has a IPS profile with all the IPS signatures selected, it does not get blocked, exploit success and user gets created on the Joomla instance.

 

I have no idea why Fortigate does not block that exploit attempt. And also I can find that specific signature in the IPS Signature database in my instance.

    1 reply

    zeromahesh
    New Member
    February 6, 2021

    Dear All,

     

    Anyone can answer my query that would be great.

    Markus
    New Member
    February 8, 2021

    Did you enabled the extended IPS package?

     

    zeromahesh
    New Member
    February 8, 2021

    Dear Markus,

    Yes Extended DB also enabled.