- Upgrade your Cisco ASA to the below versions: (Depend on your Cisco ASA support which version)9.16.4.579.18.4.229.20.2.10
- Check your firewall log or SIEM to see if there are any IOC IP hit your log.
Pages
Friday, April 26, 2024
Hackers backdoored Cisco ASA devices via two zero-days (CVE-2024-20353, CVE-2024-20359)
Wednesday, April 24, 2024
H3C firewall SSL weak cipher
Nessus vulnerability scan report about H3C firewall SSL weak cipher
Go to "Objects" -> "SSL" -> "SSL Server Policies"
You will found that even you select "TLS 1.2" and Cipher suites "High level":
SSL_RSA_with_AES_128_CBC_SHA
SSL_RSA_with_AES_256_CBC_SHA
You still false in the security scanning report and it will show weak cipher.
Solution:
Use the following 4 Cipher:
https://www.tenable.com/plugins/nessus/156899
After change the cipher under firewall GUI, then SSH to the firewall
> system-view
] undo ip https enable
] ip https enable
] save force
] exit
>
Saturday, April 20, 2024
H3C Firewall Change admin portal certificate
Wednesday, April 17, 2024
Install certificates on Symantec Messaging Gateway (SMG)
- the private key included in the PEM file
- a CSR that already exists in the SMG
Tuesday, April 16, 2024
Oracle JRE and JDK replacement
Azul Zulu OpenJDK 11 is a good choice.If your computer does not have any existing Java SE installed, it is suggested that you can download and install Azul Zulu OpenJDK 11 from the Zulu Community
The 2 amber lights followed by 4 white lights on a DELL Latitude Laptop
1. Reseat the Original Memory: If applicable to your model, reseat the original memory module in the system. Sometimes, reseating the RAM can resolve the issue.
2. Check for Damaged RAM: If reseating the RAM doesn't work, consider checking for any visible damage to the RAM sticks. If they appear damaged, you may need to replace them.
3. Firmware Updates: Ensure that your system's firmware (BIOS) is up to date. Sometimes, updating the firmware can resolve hardware-related issues.
Wednesday, April 10, 2024
Fortinet SSL VPN - SSL Certificate expired and you need to bypass tempoarilty
Configure SSL VPN to Not Require Certificates
Go to VPN > SSL > Settings > and un-check Require Client Certificate.
Thursday, April 4, 2024
Broadcom SMG - Upgrade to SGOS and Advanced Secure Gateway 7.3.19.1
Support Content Notification - Support Portal - Broadcom support portal