Dear All,
I have deployed Fortigate VM in AWS and all the licenses are active except Fortiguard. My issue is when I do a exploit to Joomla 3.4.4 instance placed behind the Fortigate VM through a Security Policy which has a IPS profile with all the IPS signatures selected, it does not get blocked, exploit success and user gets created on the Joomla instance.
I have no idea why Fortigate does not block that exploit attempt. And also I can find that specific signature in the IPS Signature database in my instance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Dear All,
Anyone can answer my query that would be great.
Did you enabled the extended IPS package?
________________________________________________________
--- NSE 4 ---
________________________________________________________
hmm, strange my screenshot was from version 5.6.12, whitch version you have installed? maybe I can check this also if it's in.
Can you upload a screenshot of your IDP policy?
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi,
Mine is 6.4.3. Please note that that specific Joomla Exploit Signature can be found in my IPS DB too. But the issue is firewall does not detect exploit.
Can you upload a screenshot of your IDP policy?
________________________________________________________
--- NSE 4 ---
________________________________________________________
Can you capture a traffic of your exploit attempt and email it to vulnwatch@fortinet.com along with your FGT config file? We can then look deeper in to the issue. If you aren't comfortable with the full config, you can just email us the information for the firewall policy and IPS sensor you are using for testing.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.