- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
symbolic link vulnerability
Hello
Recently there was a post from Fortinet PSIRT about the symlink trick:
https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
Is there any chance to get information how to find indicators of compromise (IOC)?
I mean I can update to 7.2.11 (I am currently on 7.2.10) but the used CVE's are older and I updated the fortigate before the publication of these CVE's, so there is a small chance to be compromised.
I just want to check if the fortigate is compromised, if yes, i will reinstall it. If no, I just update to 7.2.11 and have a happy life :)
Any ideas?
Solved! Go to Solution.
- Labels:
-
FortiGate
-
Vulnerability Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I think the best option here is to contact the official Fortinet support via ticket.
They can also identify exactly which devices are affected and how to check for IoCs (if possible).
KR Fabian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I think the best option here is to contact the official Fortinet support via ticket.
They can also identify exactly which devices are affected and how to check for IoCs (if possible).
KR Fabian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Fabian,
Yes, done via Ticket. They sadly don't give more information at the moment how to check for IoCs.
BR
Steve
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Great proactive approach! Hopefully, it's all clear after checking!
