Monday, June 16, 2025

Windows SMB Client Elevation of Privilege Vulnerability - CVE-2025-33073 - actively exploited in the wild

You may know the CVE-2025-33073 being reported actively exploited in the wild now.
Exploitation depends on two key conditions:







Print Friendly and PDF
Share/Bookmark

Wednesday, June 11, 2025

Azure AD Connect 2.0 change proxy setting

 1. Go to the program files -> Microsoft Azure Active Directory Connect -> To modify the file proxy config in the file "Microsoft.ApplicationProxy.Connector.Common.dll.config

2. Netsh winhttp set proxy "<proxy IP>"

3. Restart the service "Microsoft Azure AD Sync"

Then, you can run the powershell command >Start-ADSyncSyncCycle -PolicyType Initial 

To use the new proxy for the sync.

Print Friendly and PDF
Share/Bookmark

Fortinet SSL VPN customers need to be aware - Gradually transition to ZTNA while maintaining operational stability

Background on SSL VPN Deprecation in FortiOS 7.6.3
Fortinet has been advancing its Zero Trust Architecture (ZTA) strategy since 2022, introducing key Zero Trust Network Access (ZTNA) features in FortiOS 7.0. Recent versions like 7.6.3 may further prioritize ZTNA over SSL VPN. Fortinet has experienced numerous critical vulnerabilities in its SSL VPN functionality, most notably CVE-2024-21762, which allows unauthenticated remote code execution. These vulnerabilities, including older ones like CVE-2022-42475 and CVE-2023-27997, have been exploited by threat actors, leading to device compromise.

In FortiOS 7.6.3, Fortinet has deprecated and removed SSL VPN tunnel mode on all FortiGate models. This means that SSL VPN tunnel mode is no longer supported in the GUI or CLI, and existing SSL VPN configurations will not be upgraded. Users must migrate to IPsec VPN to maintain secure remote connectivity or change to use ZTNA.

If you decided to stay at FortiOS 7.4.x, it will reach end of support (EOS) on 11 May 2026. In the meantime, if you are E-series Fortigate users, you may also plan for replace your hardware to G-series when you plan for your FortiOS 7.6 journey with ZTNA.

Strategic Need to Migrate to Zero Trust (ZTNA)
Fortinet's Zero Trust Direction
  • FortiOS 7.0+ integrates ZTNA with FortiClient agents, FortiAuthenticator, and FortiOS application gateways for granular access control.
  • ZTNA aligns with hybrid cloud and SaaS environments, reducing attack surfaces compared to SSL VPN's "trusted perimeter" (Trust, but verify) model.
Technical Rationale for Transition
  • Enhanced Security : ZTNA enforces "never trust, always verify," mitigating lateral movement risks from compromised endpoints or outdated SSL configurations.
  • Performance Gains : ZTNA leverages SASE architecture, enabling low-latency, distributed access without complex tunnel management.

Options:
Short Term:

Long Term:

Reference:
For v7.6 until v7.6.2, models with 2GB or less RAM, SSL VPN web and tunnel mode are removed from the GUI and CLI. See SSL VPN to dial-up VPN migration - FortiGate 7.4.6 administration guide.
For v7.6.3 and later, tunnel mode will be removed, and web mode only works for other devices, see Migration from SSL VPN tunnel mode to IPsec VPN 7.6.3 - FortiGate 7.6.0 new features.

Print Friendly and PDF
Share/Bookmark

Saturday, May 17, 2025

中国本土信息安全认证与国际主流认证的对比

 

1. 注册信息安全专业人员(CISP vs. 国际认证

 

CISP

CISSP (ISC)²)、CISA ISACA

签发机构

中国信息安全测评中心(CNITSEC

(ISC)²ISACA

2. 注册信息安全员(CISM vs. 国际认证

 

CISM

CISM ISACA)、CompTIA Security+

签发机构

中国信息安全测评中心(CNITSEC

ISACACompTIA

3. 网络安全能力认证(CCSC/CCSRP vs. 国际认证

 

CCSC

GCIH SANS)、CEH EC-Council

签发机构

CNCERT(国家互联网应急中心)

SANSEC-Council

4. 信息安全保障人员认证(CISAW vs. 国际认证

 

CISAW

ISO 27001 LA (认证机构如PECB)、CRISC ISACA

签发机构

中国网络安全审查认证中心

PECB ISACA

5. 国家信息安全水平考试(NISP vs. 国际认证

 

NISP Level 1

CompTIA Security+ Cisco CyberOps

签发机构

中国信息安全测评中心(CNITSEC

CompTIA  Cisco

 

1. 注册信息安全专业人员(CISP- 签发机构: 中国信息安全测评中心 ( https://www.itsec.gov.cn/ryzc/)
2.
注册信息安全员(CISM - 签发机构: 中国信息安全测评中心 ( https://www.itsec.gov.cn/ryzc/)
3.
网络安全能力认证 CCSC (Previously Known: CCSRP) - 签发机构: 国家互联网应急中心 (CNCERT) ( https://www.cert.org.cn/)
4.
信息安全保障人员认证 CISAW - 签发机构:中国网络安全审查认证和市场监管大数据中心(原中国网络安全审查技术与认证中心) ( https://www.isccc.gov.cn/zxyw/shy/jcypx/xxaqbzryrz/index.shtml)
5.
国家信息安全水平考试NISP一级,NISP二级,NISP三级 - 签发机构: 中国信息安全测评中心 ( https://www.itsec.gov.cn/ryzc/) NISP全国运营管理中心 ( https://www.nisp.org.cn/)
NISP
CISP无缝对接,因为CISP报考需要工作经验,NISP认证填补了在校大学生无法考取CISP证书的空白 ( https://www.nisphome.cn/)
根据规定,持NISP二级以上证书,可免培训免考换取cisp证书 ( https://www.nisp.org.cn/NewsDetail/1547776.html)

 

Print Friendly and PDF
Share/Bookmark

Tuesday, April 1, 2025

How to test a website being protected by WAF?

Put <script>alert("123")</script> in the URL
E.g. www.abc.com/<script>alert("123")</script>


Different WAF have different block page like the following:



Print Friendly and PDF
Share/Bookmark

Saturday, March 29, 2025

Cisco ASA SSL certificate expired - Cisco Anyconnect error message


"AnyConnect cannot confirm it is connected to your secure gateway. The local network may not be trustworthy. Please try another network"

How to verify Cisco ASA SSL certificate expire or not?

Open browser to enter the URL of Cisco anyconnect to check the cert status

Print Friendly and PDF
Share/Bookmark

TencentOS Server V4 released and new security enhancement

One of the major improvements which is support Open SCAP:

scap-security-guide 新增TencentOS Server V4 安全基线配置文件

This is very good enhancement in security given that Open SCAP which is NIST certified.

Reference:

Print Friendly and PDF
Share/Bookmark