Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HA
Contributor

Fortigate affected by Firestorm Bug ??

Hi all,

 

Any info about Firestorm bug and Fortigate Firewall ??

[link]http://www.bugsec.com/news/firestorm/[/link]

 

Regards,

 

HA

1 REPLY 1
emnoc
Esteemed Contributor III

I heard of no CVEs pertaining to this  but my understanding of this issue(s) is that a SYN packet or SYN-ACK are being used to funnel data to the client+server. So to mitigated this you should never allow data within a SYN or SYN+ACK packet. ( why would we send before we have a established session

 

You can write a simple rule to block this, this vulnerability btw has NOTHING todo with NGFW it's been around for decades. What I believe has happen  is that the  underworld is not exporting this in todays attacks.

 

see my blog on how to write a IPS rule to block payload in a SYN or SYN+ACK.

 

http://socpuppet.blogspot.com/2013/01/writing-ips-rules-fortinet-style.html

 

Go down half way and review the data size option. I've used scapy in a few past lives with exposing this many years ago.

 

enjoy

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors