4 ms·
See relevant thread in r/netsec: https://www.reddit.com/r/netsec/comments/40lotk/ssh_backdoor_for_fortigate_os_version_4x_up_to/ https://www.reddit.com/r/netsec
by eeZi 11y ago
See relevant thread in r/netsec: https://www.reddit.com/r/netsec/comments/40lotk/ssh_backdoor_for_fortigate_os_version_4x_up_to/ https://www.reddit.com/r/netsec/comments/40lotk/ssh_backdoor...
> It leaves no traces in any logs (wtf?). It keeps working even if you disable "FMG-Access". It won't let you define an admin user with the same name to mitigate it, so make sure that SSH access on your devices is at least restricted to trusted hosts!
- BlackFly 11y agoThe interesting thing from that thread is that it appears it has been patched years ago. Then again, maybe they only changed the "password" in the newer versions.