Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial CVE-2022-40684 filter_list
Author
Message
CVE-2022-40684 #1
CVSS Score: 9.6

Vulnerable Fortinet product versions:

FortiOS versions between 7.0.0 - 7.0.6 and 7.2.0 - 7.2.1

FortiProxy versions between 7.0.0 - 7.0.6 and version 7.2.0

FortiSwitchManager versions 7.0.0 and 7.2.0

[Image: DMhh5f.jpg]

Reply

RE: CVE-2022-40684 #2
I don't see the link in your post?

I'd recommend using the Metasploit exploit: https://packetstormsecurity.com/files/16...ypass.html

Reply

RE: CVE-2022-40684 #3
(10-26-2022, 09:17 AM)fritz Wrote: I don't see the link in your post?
Obviously forgot to post It.

I've come across countless users over the last decade who did the same.
[Image: AD83g1A.png]

Reply

RE: CVE-2022-40684 #4
(10-26-2022, 09:42 AM)mothered Wrote:
(10-26-2022, 09:17 AM)fritz Wrote: I don't see the link in your post?
Obviously forgot to post It.

I've come across countless users over the last decade who did the same.
Seems to be a pattern with this user (bot?) though.
https://sinister.ly/Thread-Leak-Google-C...e-Metadata
https://sinister.ly/Thread-Leak-CodeMete...-Dashboard
...
I believe they're originally all supposed to be from blog.criminalip.io, but it looks like his script is broken Wink


About the original subject, I don't know much about Fortinet, but it could be interesting to the community to also have a way to identify potential vulnerable servers (search for open ports or hints in google search for example).
Seeing the exploit code it seems it only checks if random path is 401 protected and that a "fortinet-formatted" request to /system/status does return a 200.

Reply

RE: CVE-2022-40684 #5
(10-26-2022, 11:53 AM)fritz Wrote: Seems to be a pattern with this user (bot?) though.
https://sinister.ly/Thread-Leak-Google-C...e-Metadata
https://sinister.ly/Thread-Leak-CodeMete...-Dashboard
Not sure offhand.

I'll need to assess his/her activity.

(10-26-2022, 11:53 AM)fritz Wrote: About the original subject, I don't know much about Fortinet, but it could be interesting to the community to also have a way to identify potential vulnerable servers (search for open ports or hints in google search for example).
Absolutely.

I couldn't agree more.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: CVE-2022-40684 #6
(10-26-2022, 09:17 AM)fritz Wrote: I don't see the link in your post?

I'd recommend using the Metasploit exploit: https://packetstormsecurity.com/files/16...ypass.html

Found using criminal ip's asset search - https://www.criminalip.io/

Reply

RE: CVE-2022-40684 #7
(10-28-2022, 01:43 AM)zwriner Wrote: Found using criminal ip's asset search - https://www.criminalip.io/
It's best to add the link to your opening post.
[Image: AD83g1A.png]

Reply

RE: CVE-2022-40684 #8
(10-28-2022, 02:47 AM)mothered Wrote:
(10-28-2022, 01:43 AM)zwriner Wrote: Found using criminal ip's asset search - https://www.criminalip.io/
It's best to add the link to your opening post.
My bad I'll keep that in mind next time. Thank you!

Reply

RE: CVE-2022-40684 #9
thanks a lot.... been looking for this
Join Our Telegram Channel - https://t.me/addlist/wgi1gS3LkLtkNjJk

Reply

RE: CVE-2022-40684 #10
Moving this to Website & Server Hacking.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply