<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SSL &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Mon, 31 Jul 2023 07:49:32 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>Windows Admin Center更換SSL憑證</title>
		<link>https://ailog.tw/lifelog/2023/07/23/wac-ssl/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 23 Jul 2023 11:21:23 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Change]]></category>
		<category><![CDATA[renew]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Windows Admin Center]]></category>
		<category><![CDATA[憑證]]></category>
		<category><![CDATA[更換]]></category>
		<category><![CDATA[更新]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=16356</guid>

					<description><![CDATA[Windows Admin Center新一代的伺服器管理工具，支援透過WEB來進行伺服器管理，操作介面也十分 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2023/07/23/wac-ssl/" class="more-link">閱讀全文<span class="screen-reader-text">〈Windows Admin Center更換SSL憑證〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>Windows Admin Center新一代的伺服器管理工具，支援透過WEB來進行伺服器管理，操作介面也十分相似AZure管理介面，算是一套相當好上手的管理軟體，不過畢竟是透過web來提供服務，因此就會有SSL憑證過期的問題，小編今天就是要來介紹如何替換Windows Admin Center的SSL憑證。<span id="more-16356"></span></p>
<p><span style="font-family: verdana, geneva; color: #0000ff;"><strong>一、將新的憑證先匯入伺服器</strong></span><br />
01、選擇要匯入的憑證檔案，點選滑鼠右鍵「安裝PFX」<br />
<img fetchpriority="high" decoding="async" class="alignnone wp-image-16359 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-00.png" alt="" width="407" height="168" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-00.png 407w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-00-300x124.png 300w" sizes="(max-width: 407px) 100vw, 407px" /></p>
<p>&nbsp;</p>
<p>02、選擇「本機電腦」<br />
<img decoding="async" class="alignnone wp-image-16382 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-01-1.png" alt="" width="611" height="576" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-01-1.png 611w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-01-1-300x283.png 300w" sizes="(max-width: 611px) 100vw, 611px" /></p>
<p>03、憑證檔案路徑無誤的話，就點選「下一步」<br />
<img decoding="async" class="alignnone wp-image-16383 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-02-e1690110545714.png" alt="" width="610" height="576" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-02-e1690110545714.png 610w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-02-e1690110545714-300x283.png 300w" sizes="(max-width: 610px) 100vw, 610px" /></p>
<p>&nbsp;</p>
<p>04、輸入憑證密碼(如憑證無密碼則無需填寫)，勾選「包含所有延伸內容」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16384 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-03.png" alt="" width="599" height="567" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-03.png 599w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-03-300x284.png 300w" sizes="auto, (max-width: 599px) 100vw, 599px" /></p>
<p>&nbsp;</p>
<p>05、點選「將所有憑證放入以下的存放區」來指定憑證存放位置<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16385 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-04.png" alt="" width="599" height="342" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-04.png 599w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-04-300x171.png 300w" sizes="auto, (max-width: 599px) 100vw, 599px" /></p>
<p>&nbsp;</p>
<p>06、選擇「個人」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16387 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-05-1.png" alt="" width="576" height="353" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-05-1.png 576w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-05-1-300x184.png 300w" sizes="auto, (max-width: 576px) 100vw, 576px" /></p>
<p>&nbsp;</p>
<p>07、確認憑證存放位置為「個人」後，點選「下一步」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16388 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-06.png" alt="" width="608" height="573" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-06.png 608w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-06-300x283.png 300w" sizes="auto, (max-width: 608px) 100vw, 608px" /></p>
<p>&nbsp;</p>
<p>08、點選「完成」開始匯入憑證<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16389 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-07.png" alt="" width="611" height="579" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-07.png 611w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-07-300x284.png 300w" sizes="auto, (max-width: 611px) 100vw, 611px" /></p>
<p>&nbsp;</p>
<p>09、匯入成功的話可以看見下圖「匯入執行成功」的提示<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16390 size-medium" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-08-300x209.png" alt="" width="300" height="209" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-08-300x209.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-08.png 311w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva; color: #0000ff;"><strong>二、變更Windows Admin Center憑證設定</strong></span><br />
01、開啟「控制台」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16367 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-01.png" alt="" width="120" height="87" /></p>
<p>&nbsp;</p>
<p>02、開啟「程式和功能」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16368 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-02.png" alt="" width="451" height="198" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-02.png 451w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-02-300x132.png 300w" sizes="auto, (max-width: 451px) 100vw, 451px" /></p>
<p>03、選擇「Windows Admin Center」後，點選「變更」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16369 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-03.png" alt="" width="468" height="293" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-03.png 468w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-03-300x188.png 300w" sizes="auto, (max-width: 468px) 100vw, 468px" /></p>
<p>&nbsp;</p>
<p>04、選擇「下一步」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16370 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-04.png" alt="" width="493" height="393" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-04.png 493w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-04-300x239.png 300w" sizes="auto, (max-width: 493px) 100vw, 493px" /></p>
<p>&nbsp;</p>
<p>05、選擇「變更」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16371 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-05.png" alt="" width="489" height="381" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-05.png 489w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-05-300x234.png 300w" sizes="auto, (max-width: 489px) 100vw, 489px" /></p>
<p>&nbsp;</p>
<p>06、輸入下方PowerShell的憑證查詢指令</p>
<pre class="code">Get-ChildItem -Path Cert:\LocalMachine\MY</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-16391 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-05-1.png" alt="" width="639" height="220" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-05-1.png 639w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-05-1-300x103.png 300w" sizes="auto, (max-width: 639px) 100vw, 639px" /><br />
※將步驟一匯入憑證的憑證指紋複製，下一個步驟需要使用。</p>
<p>&nbsp;</p>
<p>07、在「提供閘道SSL憑證的指紋」欄位貼入上一步驟取得的憑證指紋，並點選「變更」進行憑證替換作業<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-16378 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-06-e1690110176413.png" alt="" width="492" height="392" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-06-e1690110176413.png 492w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-06-e1690110176413-300x239.png 300w" sizes="auto, (max-width: 492px) 100vw, 492px" /></p>
<p>&nbsp;</p>
<p>08、下圖為憑證更換過程畫面</p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-16380 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-07.png" alt="" width="492" height="391" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-07.png 492w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-07-300x238.png 300w" sizes="auto, (max-width: 492px) 100vw, 492px" /></p>
<p>&nbsp;</p>
<p>09、下圖為憑證更換完成畫面，點選「完成」結束憑證替換作業</p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-16381 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-08.png" alt="" width="494" height="392" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-08.png 494w, https://ailog.tw/lifelog/wp-content/uploads/2023/07/wac-ssl-2-08-300x238.png 300w" sizes="auto, (max-width: 494px) 100vw, 494px" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate SSL VPN漏洞(CVE-2021-26092)</title>
		<link>https://ailog.tw/lifelog/2021/06/05/cve-2021-26092/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 05 Jun 2021 05:16:49 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE-2021-26092]]></category>
		<category><![CDATA[FG-IR-20-199]]></category>
		<category><![CDATA[FortiGate SSL VPN]]></category>
		<category><![CDATA[FortiGate SSL VPN漏洞(CVE-2021-26092)]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[漏洞]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8970</guid>

					<description><![CDATA[FortiGate SSL VPN漏洞(CVE-2021-26092)，原廠在2021年5月30日已釋出解決方 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/06/05/cve-2021-26092/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate SSL VPN漏洞(CVE-2021-26092)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">FortiGate SSL VPN漏洞(CVE-2021-26092)，原廠在2021年5月30日已釋出解決方案，有啟用SSL VPN的網友，可以參考一下相關風險的解決方案。<span id="more-8970"></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">發布日期：2021年05月30日</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">IR號碼：FG-IR-20-199</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">影響：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">在SSL VPN web portal的網頁上有Cross-site Scripting (XSS)的弱點，可能允許未經身份驗證的遠程攻擊者送帶有惡意GET參數進而達到跨站點腳本 (XSS) 攻擊。</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">受影響的產品：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS 5.6系列：FortiGate 5.6.13及以下版本。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS 6.0系列：FortiGate 6.0.12及以下版本。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS 6.2系列：FortiGate 6.2.7及以下版本。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS 6.4系列：FortiGate 6.4.5及以下版本。</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">解決方案：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">請升級到 FortiGate 6.0.13 或更高版本。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">請升級到 FortiGate 6.2.8 或更高版本。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">請升級到 FortiGate 6.4.6 或更高版本。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">請升級到 FortiGate 7.0.0 或更高版本。</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">臨時性方案：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">關閉SSL-VPN web認證畫面。</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">原廠說明網址：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://www.fortiguard.com/psirt/FG-IR-20-199">https://www.fortiguard.com/psirt/FG-IR-20-199</a></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>因應疫情遠距上班，企業開放VPN前請先檢查是否有漏洞尚未修補。</title>
		<link>https://ailog.tw/lifelog/2020/03/25/sslvpn/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Wed, 25 Mar 2020 15:14:18 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[因應疫情遠距上班，企業開放VPN前請先檢查是否有漏洞尚未修補。]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=2722</guid>

					<description><![CDATA[COVID-19疫情持續升溫，許多企業紛紛籌備遠距上班的方案，其中最常見的方法為透過VPN讓員工可以連線回公司 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2020/03/25/sslvpn/" class="more-link">閱讀全文<span class="screen-reader-text">〈因應疫情遠距上班，企業開放VPN前請先檢查是否有漏洞尚未修補。〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>COVID-19疫情持續升溫，許多企業紛紛籌備遠距上班的方案，其中最常見的方法為透過VPN讓員工可以連線回公司存取企業內部資源<span id="more-2722"></span>，但在開放VPN服務前，小編提醒大家記得先檢查一下VPN設備是否有完成漏洞更新，避免服務開放後又掀起另一波災情。</p>
<p>OpenVPN：CVE-2019-14899<br />
<a href="https://securityboulevard.com/2019/12/statement-from-protonvpn-regarding-cve-2019-14899/">https://securityboulevard.com/2019/12/statement-from-protonvpn-regarding-cve-2019-14899/</a></p>
<p>Fortigate：CVE-2018-13379 (FG-IR-18-384) 及CVE-2018-13383 (FG-IR-18-388)<br />
<a href="https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&amp;docType=kc&amp;externalId=FD46513">https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&amp;docType=kc&amp;externalId=FD46513</a></p>
<p>CISCO：CVE-2019-12677<br />
<a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-ssl-vpn-dos">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-ssl-vpn-dos</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate SSL VPN漏洞(CVE-2018-13381)</title>
		<link>https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13381/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 16 Sep 2019 05:16:31 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE-2018-13381]]></category>
		<category><![CDATA[FG-IR-18-387]]></category>
		<category><![CDATA[FortiGate SSL VPN]]></category>
		<category><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13381)]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[漏洞]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=866</guid>

					<description><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13381)，原廠在2019年5月份已釋出解決方案， &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13381/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate SSL VPN漏洞(CVE-2018-13381)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate SSL VPN漏洞(CVE-2018-13381)，原廠在2019年5月份已釋出解決方案，有啟用SSL VPN的網友，可以參考一下相關風險的解決方案。<span id="more-866"></span></p>
<p>發布日期：2019年5月17日<br />
IR號碼：FG-IR-18-387</p>
<p>影響：<br />
如果未能在FortiOS的SSL VPN認證頁面中正確解析消息有效負載，則可能允許未經過身份驗證的攻擊者通過利用緩衝區溢出來執行拒絕服務攻擊(DoS)。</p>
<p>受影響的產品：<br />
FortiOS 6.0系列：6.0.0至6.0.4。<br />
FortiOS 5.6系列：5.6.0至5.6.7。<br />
FortiOS 5.4系列：5.4及以下版本。</p>
<p>解決方案：<br />
直接升級到6.2.0或參考下列各版更新資訊。<br />
FortiOS 6.0系列：升級到6.0.5或更高版本。<br />
FortiOS 5.6系列：升級到5.6.8或更高版本。</p>
<p>臨時性方案：<br />
關閉SSL-VPN web認證畫面</p>
<p>原廠說明網址：<br />
<a href="https://fortiguard.com/psirt/FG-IR-18-387">https://fortiguard.com/psirt/FG-IR-18-387</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate SSL VPN漏洞(CVE-2018-13380)</title>
		<link>https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13380/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 16 Sep 2019 05:11:54 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE-2018-13380]]></category>
		<category><![CDATA[FG-IR-18-383]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13380)]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=864</guid>

					<description><![CDATA[FortiGate  SSL VPN漏洞(CVE-2018-13380)，原廠在2019年5月份已釋出解決方案 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13380/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate SSL VPN漏洞(CVE-2018-13380)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate  SSL VPN漏洞(CVE-2018-13380)，原廠在2019年5月份已釋出解決方案，有啟用SSL VPN的網友，可以參考一下相關風險的解決方案。<span id="more-864"></span></p>
<p>發布日期：2019年5月24日<br />
IR號碼：FG-IR-18-383</p>
<p>影響：<br />
未能清除SSL VPN Web認證畫面中的錯誤或消息處理參數可能允許攻擊者執行跨站點腳本(XSS)攻擊。</p>
<p>受影響的產品：<br />
FortiOS 6.0系列：6.0.0至6.0.4。<br />
FortiOS 5.6系列：5.6.0至5.6.7。<br />
FortiOS 5.4系列：5.4及以下版本。</p>
<p>解決方案：<br />
直接升級到6.2.0或參考下列各版更新資訊。<br />
FortiOS 6.0系列：升級到6.0.5或更高版本。<br />
FortiOS 5.6系列：升級到5.6.8或更高版本。</p>
<p>臨時性方案：<br />
關閉SSL-VPN web認證畫面</p>
<p>原廠說明網址：<br />
https://fortiguard.com/psirt/FG-IR-18-383</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate SSL VPN漏洞(CVE-2018-13382)</title>
		<link>https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13382/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 16 Sep 2019 04:32:42 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE-2018-13382]]></category>
		<category><![CDATA[FG-IR-18-389]]></category>
		<category><![CDATA[FortiGate SSL VPN]]></category>
		<category><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13382)]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[漏洞]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=862</guid>

					<description><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13382)，原廠在2019年5月份已釋出解決方案， &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13382/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate SSL VPN漏洞(CVE-2018-13382)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate SSL VPN漏洞(CVE-2018-13382)，原廠在2019年5月份已釋出解決方案，有啟用SSL VPN的網友，可以參考一下相關風險的解決方案。<span id="more-862"></span></p>
<p>發布日期：2019年5月24日<br />
IR號碼：FG-IR-18-389</p>
<p>影響：<br />
當啟用SSL VPN功能(Web模式或隧道模式)且使用本地端身份驗證時才受影響，SSL VPN Web驗證畫面中的不正當授權漏洞可能允許未經身份驗證的攻擊者通過特製的HTTP請求更改SSL VPN Web驗證畫面用戶的密碼。</p>
<p>受影響的產品：<br />
FortiOS 6.0系列：6.0.0至6.0.4。<br />
FortiOS 5.6系列：5.6.0至5.6.8。<br />
FortiOS 5.4系列：5.4.1至5.4.10。<br />
備註：5.4.0及以下版本(包括分支5.2)不受影響。</p>
<p>解決方案：<br />
直接升級到6.2.0或參考下列各版更新資訊。<br />
FortiOS 6.0系列：升級到6.0.5或更高版本。<br />
FortiOS 5.6系列：升級到5.6.9或更高版本。<br />
FortiOS 5.4系列：升級到5.4.11或更高版本。</p>
<p>臨時性方案：<br />
(1)、關閉SSL VPN功能。<br />
(2)、SSL VPN使用者身份驗證從本地移轉到到LDAP(Windows AD)或RADIUS遠端認證主機。</p>
<p>原廠說明網址：<br />
<a href="https://fortiguard.com/psirt/FG-IR-18-389">https://fortiguard.com/psirt/FG-IR-18-389</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate SSL VPN漏洞(CVE-2018-13383)</title>
		<link>https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13383/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 16 Sep 2019 04:22:22 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE-2018-13383]]></category>
		<category><![CDATA[FG-IR-18-388]]></category>
		<category><![CDATA[FortiGate SSL VPN]]></category>
		<category><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13383)]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[漏洞]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=860</guid>

					<description><![CDATA[FortiGate SSL VPN漏洞(CVE-2018-13379)，原廠在2019年4月份已釋出解決方案， &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2019/09/16/fortigate-ssl-cve-2018-13383/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate SSL VPN漏洞(CVE-2018-13383)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate SSL VPN漏洞(CVE-2018-13379)，原廠在2019年4月份已釋出解決方案，有啟用SSL VPN的網友，可以參考一下相關風險的解決方案。<span id="more-860"></span></p>
<p>發布日期：2019年4月2日<br />
IR號碼：FG-IR-18-388</p>
<p>影響：<br />
只影響SSL VPN Web模式(SSL VPN隧道模式不受影響)，FortiOS SSL VPN Web中的堆緩衝區溢出漏洞，可能導致登錄用戶終止SSL VPN Web服務或FortiOS上潛在的遠程程式碼執行；當經過身份驗證的使用者訪問專門設計的代理網頁時會發生這種情況，這是因為無法正確處理javascript href內容。</p>
<p>受影響的產品：<br />
FortiOS 6.0系列：6.0.0到6.0.4<br />
FortiOS 5.6.10及以下版本</p>
<p>解決方案：<br />
直接升級到6.2.0或參考下列各版更新資訊。<br />
FortiOS 6.0系列：升級到6.0.5或更高版本。<br />
FortiOS 5.6系列：升級到5.6.11或更高版本。</p>
<p>臨時性方案：<br />
(1)、只使用SSL VPN隧道模式。<br />
(2)、在SSL VPN Web模式下只連線受信任的HTTP Web Server。</p>
<p>原廠說明網址：<br />
<a href="https://fortiguard.com/psirt/FG-IR-18-388">https://fortiguard.com/psirt/FG-IR-18-388</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
