Security Researcher, Recovering Red Teamer, Speaker & Author. Former LULZSEC Member. Cofounder @bsidespeoria & IL Cyber Foundation. Views expressed are my own.
@Mandiant Some new refined searches get this total closer to 5,000 Internet exposed #fortimanager devices. The average device count in the hundreds would mean 500,000 or more potentially impacted devices.
Yesterdays headline about the #FortiManager#Vulnerability included a stat: 60,000 vulnerable devices. That may have been a bit misleading. You see, the search done on Shodan identified devices that likely *receive* updates from FortiManager using port 541+some magic.
@Mandiant Also, stop putting shit on the internet on non-standard ports like its going to do something. 4443, 8443, and 10443 isn't going to hide the service from anyone. All you're doing is making it take a little longer to script and make it 1% harder for the bad guys to #badguy.
@UK_Daniel_Card Not to mention how absolutely tragic Fortinet's response was and how they "handled" this patch. I've not talked to one admin who has been happy with the communication around it.
This FortiManager vulnerability is *wild* folks. Trivial to exploit, impacts are incredibly bad.
If you haven't patched already I'd be doing it ASAP and check the logs for the bad guys.
Man, I cannot believe we're one week away already.
We've got some pre-event announcements coming but only a few tickets left. So get them while you can.