Exploits and vulnerabilities. [Research Saturday]
Description
Ryan from Bishop Fox joins to describe their work on "Building an Exploit for FortiGate Vulnerability CVE-2023-27997." After Lexfo published details of a pre-authentication remote code injection vulnerability in the Fortinet SSL VPN, Bishop Fox worked up a proof of concept demo.
This research share how they were able to create that proof-of-concept exploit, step by step. The researchers state "Our debugging environment consisted of a FortiGate 7.2.4 virtual machine which we modified to disable some self-verification functionality. After bypassing these integrity checks, we were able to install an SSH server, BusyBox, and debugging tools such as GDB."
The research can be found here:
Learn more about your ad choices. Visit megaphone.fm/adchoices

![Exploits and vulnerabilities. [Research Saturday] Exploits and vulnerabilities. [Research Saturday]](https://static.libsyn.com/p/assets/4/e/e/f/4eef90b1aa7119ee/cyberwire-daily-cover-art-cw.jpg)



















![Trends in COVID-19-themed cybercrime. Social media seek to inhibit the misinformation pandemic. Corp[dot] off the market. BEC in cloud services. Investment notes. Big big fraud. Trends in COVID-19-themed cybercrime. Social media seek to inhibit the misinformation pandemic. Corp[dot] off the market. BEC in cloud services. Investment notes. Big big fraud.](https://megaphone.imgix.net/podcasts/632bbe26-def8-11ea-911f-db47d72e494e/image/daily-podcast-cover-art-cw.jpg?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress)


