Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
symbolic link vulnerability and IPS
Good Morning,
There were post about the symbolic link vulnerability on Fortigate recently, the document mentioned the updated AV / IPS can remove the bad symbolic link.
I want to know if there is AV/ IPS event tell us, the bad symbolic link detected and has been removed ?
How to check if bad symbolic link exists in the file system ?
Regards,
Jacky
Labels:
- Labels:
-
FortiGate
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jacky
Please check this PSIRT article.
https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
AEK
AEK
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I have read this document but it does not provide the log / event sample about AV/IPS removed the bad symbolic link .
If the AV/ IPS removed the bad symbolic link , is there any log / event I can check ?
