FortiWeb 认证绕过检测产物生成器
有关技术细节,请参阅我们的博客文章
python watchTowr-vs-Fortiweb-AuthBypass.py 192.168.1.99
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__/
\/ \/ \/
watchTowr-vs-Fortiweb-AuthBypass.py
(*) FortiWeb Authentication Bypass Artifact Generator
- Sina Kheirkhah (@SinSinology) and Jake Knott (@inkmoro) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2025-xxxxx]
[+] Exploit sent successfully.
[*] Check for the new user [ 35f36895 ] with password [ 35f36895 ]
该脚本用于检测 FortiWeb 是否存在认证绕过漏洞。
低于 8.0.2 的 FortiWeb 版本受到影响,如需了解更具体的版本,请联系 FortiGuard Labs PSIRT。
如需获取最新的安全研究,请关注 watchTowr 实验室团队