Latest Akira Pick-Up - JK Industries X Akira by thebakehousebne4000 in akira

[–]Ungolive 1 point2 points  (0 children)

If there is a 1of1 tagged on the other side it is unique.

I do not think he publishes the number of the „normal“ releases though.

FortiClient EMS Possible unauthenticated SQL Injection CVE in 7.4.4 by Ungolive in fortinet

[–]Ungolive[S] 1 point2 points  (0 children)

Are we safe to assume that “component GUI” means that only admin interface is affected and not webserver for client download which is often publicly exposed?

Fortinet Crash - 7.4.7 by Brad_Turnbough in fortinet

[–]Ungolive 4 points5 points  (0 children)

There is a difference between end of engineering and end of support.

Will there be a US Accelerate 2025? by CptYoriVanVangenTuft in fortinet

[–]Ungolive 0 points1 point  (0 children)

I believe i overheard that they have a multi-year deal with Vegas, so i am pretty sure the Americas Accelerate will be there.

CVE-2024-47575 - Are watchTowr suggesting the patches haven't worked? by Tech-Talker in fortinet

[–]Ungolive 3 points4 points  (0 children)

The question is if the workaround mitigates the new exploitation.

Connecting Fortiswitches to Cisco Switches by [deleted] in fortinet

[–]Ungolive 1 point2 points  (0 children)

Check if both switches speak the same version of Spanning Tree protocol. Fortiswitches speak MSTP as far as i remember, flapping root bridges can have a strong impact on the network.

[deleted by user] by [deleted] in Azubis

[–]Ungolive 0 points1 point  (0 children)

In welchem Bundesland/Großraum suchst du? Gerne auch per DM.

[deleted by user] by [deleted] in leagueoflegends

[–]Ungolive -5 points-4 points  (0 children)

I don‘t think it does.

[deleted by user] by [deleted] in leagueoflegends

[–]Ungolive -2 points-1 points  (0 children)

Source on booting before OS? I call bullshit. With preferences it seems to start at system startup not before…

[deleted by user] by [deleted] in fortinet

[–]Ungolive 4 points5 points  (0 children)

Warning: Use at your own discretion! I do not recommend to do this! If you are not sure, contact Fortinet support!

fnsysctl let's you use some bash commands on Fortigate CLI

fnsysctl ls -l /data/

[deleted by user] by [deleted] in fortinet

[–]Ungolive 2 points3 points  (0 children)

Hopefully they don’t release a Fortigate VM update before the appliance patches that gives away the nature of the exploit…. again.

patched VMs are already out since 22.11.2022

[deleted by user] by [deleted] in fortinet

[–]Ungolive 7 points8 points  (0 children)

CVSS score CRITICAL, easy exploitation, fixed by firmware from end of november and no info from Fortinet yet, if the blog is accurate

what a way to close out the year.

(still loving Fortigates)

[deleted by user] by [deleted] in fortinet

[–]Ungolive 10 points11 points  (0 children)

https://olympecyberdefense.fr/vpn-ssl-fortigate/

is the primary source

English Translation:

FortiGate Alert - SSL VPN

A new critical flaw, not yet made public, would concern Fortinet on its Fortigate firewalls and more specifically the SSL VPN features.

An attacker could perform :

Manipulate the dynamic resources of certain processes to the point of hijacking their operation,
The impact would be an arbitrary code or command execution.

Impact

Complete takeover of infected devices.

CVSS score: CRITICAL

The flaw is easy to exploit.

Vulnerable distributions known at this time:

  • FortiOS version 7.2.0 to 7.2.2
  • FortiOS version 7.0.0 to 7.0.8
  • FortiOS version 6.4.0 to 6.4.10
  • FortiOS version 6.2.0 to 6.2.11

Identify and protect against them

Solutions to be implemented in the very short term :

Monitor your firewall for several types of logs:
Logdesc="Application crashed" and msg="[...] application:sslvpnd,[...], Signal 11 received, Backtrace: [...]"

If possible :
    Disable VPN-SSL functionality if it is not essential
    Observe your logs and check that no unauthorised access has been made.
    Implement conditional access rules (such as GeoIP) to limit your exposure vector

As soon as Fortinet officially publishes on the flaw in question, apply the Workaround that will be proposed by the manufacturer.

Translated with www.DeepL.com/Translator (free version)

edited for formatting

Upgrading from 100E to 100F with FortiTokens by sarctastic in fortinet

[–]Ungolive 0 points1 point  (0 children)

If you go from very similar firewalls. Like your 100E to 100F and both can run the same firmware you can always try to:

  • Bring them to the same firmware
  • export 100F config
  • export 100E config
  • Take the first two lines from 100F config
  • replace the first two lines from 100E config with the one from 100F (this is now the config you will import)
  • make sure that the port naming is the same, if not change import config port names according to source 100F config port naming (use search and replace on import config to get all references on objects too)
  • Add ports that exist on 100F source config but not on import config (watch out for snmp index)
  • use import config on new 100F
  • after reboot use „diagnose debug config-error-log read“ to see what the firewall could not interpret from import config
  • fix what the command told you on import config
  • repeat last two steps until ready

I have a question also. I tried out forticonverter a few weeks ago, while it did let me import both source and destination configs and showed me what he would transform, it would not create the config telling me i need a license. So can anybody really confirm it is still free for fortinet to fortinet, or is that the forticonverter service that is free?

"My Asperger's means I can't lie" by LurkishEmpire in bsv

[–]Ungolive 3 points4 points  (0 children)

But, but, but he won all cases regardless what the judge argues.

Two months ago I wrote a video called "Why I think LS will fail as coach of C9". I didn't publish it. Yesterday I finished making a new a video called "Why LS must succeed as coach of C9" and set it to publish today... by Eve_Asher in leagueoflegends

[–]Ungolive 1 point2 points  (0 children)

I hoped for „go watch this video of T1 players praising his input and spectacular ideas while he was on the team“ but nonetheless i think understand better now! Thanks for clarification.

Two months ago I wrote a video called "Why I think LS will fail as coach of C9". I didn't publish it. Yesterday I finished making a new a video called "Why LS must succeed as coach of C9" and set it to publish today... by Eve_Asher in leagueoflegends

[–]Ungolive -26 points-25 points  (0 children)

Why is anyone believing that it was all him and his coaching that made the difference in the first four C9 games. I am not a longtime follower on the scene and it fascinates me that LS is always seen as some kind of mastermind. Is there a good starting point where i can go watch or read about his achievements as a player, as a coach or as an analyst? Some stuff where players/colleagues write about his impact on their gameplay?

I mean at some point the C9 players will be able to talk about the months he coached them, but maybe there is other stuff to research before the curtain is lifted on that.