Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
BID:10480
Info
Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
| Bugtraq ID: | 10480 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2002 12:00AM |
| Updated: | May 05 2002 12:00AM |
| Credit: | This issue was reported by Microsoft. |
| Vulnerable: |
Microsoft ISA Server 2000 SP1 Microsoft ISA Server 2000 |
| Not Vulnerable: |
Microsoft ISA Server 2000 SP2 |
Discussion
Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
Microsoft Internet Security and Acceleration (ISA) Server 2000 is prone to a vulnerability that may permit malicious users to bypass administrator defined Site and Content rules.
The result of this problem is that URIs may bypass the proxy server's filter if they include an extraneous period character after the domain. This may let users circumvent security policy and gain access to remote sites that have been restricted by the proxy server.
Microsoft Internet Security and Acceleration (ISA) Server 2000 is prone to a vulnerability that may permit malicious users to bypass administrator defined Site and Content rules.
The result of this problem is that URIs may bypass the proxy server's filter if they include an extraneous period character after the domain. This may let users circumvent security policy and gain access to remote sites that have been restricted by the proxy server.
Exploit / POC
Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
This issue could be exploited with a network client such as a web browser. The following example was provided:
www.example.com.
This may permit a malicious user to access www.example.com if there was a rule to prevent such access.
This issue could be exploited with a network client such as a web browser. The following example was provided:
www.example.com.
This may permit a malicious user to access www.example.com if there was a rule to prevent such access.
Solution / Fix
Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
Solution:
Microsoft has released ISA Server 2000 SP2 to address this and other issues. Users are advised to upgrade.
Microsoft ISA Server 2000 SP1
Solution:
Microsoft has released ISA Server 2000 SP2 to address this and other issues. Users are advised to upgrade.
Microsoft ISA Server 2000 SP1
-
Microsoft Internet Security and Acceleration (ISA) Server 2000 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyID=c8d3d98b-1cd4 -406a-a04a-2aa2547d09a3&DisplayLang=en
References
Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
References:
References:
- Incorrect Canonicalization in Rules Engine (Microsoft)