Cody Kretsinger

705 posts

Cody Kretsinger banner
Cody Kretsinger

Cody Kretsinger

@CodyKretsinger

Security Researcher, Recovering Red Teamer, Speaker & Author. Former LULZSEC Member. Cofounder @bsidespeoria & IL Cyber Foundation. Views expressed are my own.

Katılım Haziran 2014
460 Takip Edilen348 Takipçiler
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
Real American Patriots support Ukraine. We're with you @ZelenskyyUa 🇺🇦Slava Ukraini🇺🇦
English
1
0
0
95
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
We've made it to Gleba and made some much needed design choices that are familiar, but I just can't quite put my finger on where I know it from...
Cody Kretsinger tweet media
English
0
0
1
141
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
@Mandiant Some new refined searches get this total closer to 5,000 Internet exposed #fortimanager devices. The average device count in the hundreds would mean 500,000 or more potentially impacted devices.
English
0
0
0
75
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
@Mandiant Also, stop putting shit on the internet on non-standard ports like its going to do something. 4443, 8443, and 10443 isn't going to hide the service from anyone. All you're doing is making it take a little longer to script and make it 1% harder for the bad guys to #badguy.
English
1
0
0
77
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
Yesterdays headline about the #FortiManager #Vulnerability included a stat: 60,000 vulnerable devices. That may have been a bit misleading. You see, the search done on Shodan identified devices that likely *receive* updates from FortiManager using port 541+some magic.
Cody Kretsinger tweet media
English
1
0
2
485
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
@UK_Daniel_Card Not to mention how absolutely tragic Fortinet's response was and how they "handled" this patch. I've not talked to one admin who has been happy with the communication around it.
English
0
1
3
920
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@CodyKretsinger Also just the fact this exists will have imposed cost and diverted attention from other things…
English
1
0
0
76
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
@UK_Daniel_Card You're 100% spot on. And its only going to take a couple of these appliances getting popped to cause an absolute mess.
English
1
0
1
59
mRr3b00t
mRr3b00t@UK_Daniel_Card·
the FGFM Port + XAB or something query was probably a good idea of potential targets then as you say: how many firewalls are they managing. you can tell from the NCSC notice (if you read between the lines) how this might look... it's very complex from an external pov to know... I would imagine even Fortinet don't really know either.
English
1
0
1
78
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
This FortiManager vulnerability is *wild* folks. Trivial to exploit, impacts are incredibly bad. If you haven't patched already I'd be doing it ASAP and check the logs for the bad guys.
Cody Kretsinger tweet media
English
0
4
14
1.6K
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
Todays a 'coffee run start' kind of day
English
0
0
0
48
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
@TomLawrenceTech ok, good. I'm not alone then! Next question, do you all do it in front of execs as well?
English
0
0
0
16
Cody Kretsinger
Cody Kretsinger@CodyKretsinger·
Does anyone else call "incognito" or "private browsing" Porn Mode or is it just me?
English
1
0
3
364