Description |
This article provides the response of Fortinet for the mnemonic report SNIcat: Circumventing the guardians.
Related document. |
Scope |
|
Solution |
The main concern of the blog is that the TLS Client Hello packet always reaches the destination server, even if the domain accessed is blacklisted/blocked by a webfilter category in the firewall.
The firewall only blocks the session after the TLS handshake had been completed, but not earlier.
To prevent the exploit from getting into the network and to detect the traffic patterns of the commands sent by the tool, Fortinet issued the following signatures respectively: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.