Multiple IDS Vendor Encoded IIS Attack Detection Evasion Vulnerability
BID:3292
Info
Multiple IDS Vendor Encoded IIS Attack Detection Evasion Vulnerability
| Bugtraq ID: | 3292 |
| Class: | Environment Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2001 12:00AM |
| Updated: | Sep 05 2001 12:00AM |
| Credit: | Credited to 'hsj' as being used in proof of concept code for an unrelated vulnerability. Further research conducted by eEye Digital Security. |
| Vulnerable: |
Snort Project Snort 1.8 Snort Project Snort 1.7 Snort Project Snort 1.6.3 Snort Project Snort 1.6.2 Snort Project Snort 1.6.1 Snort Project Snort 1.6 Snort Project Snort 1.5.2 Snort Project Snort 1.5.1 Snort Project Snort 1.5 NFR Network Intrusion Detection 5.0 Internet Security Systems RealSecure Server Sensor 6.0 Win Internet Security Systems RealSecure Server Sensor 5.5.2 Win Internet Security Systems RealSecure Server Sensor 5.5.1 Win Internet Security Systems RealSecure Server Sensor 5.5 Win Internet Security Systems RealSecure Server Sensor 5.0 Win Internet Security Systems RealSecure Network Sensor 6.0 Internet Security Systems RealSecure Network Sensor 5.5.2 Internet Security Systems RealSecure Network Sensor 5.5.1 Internet Security Systems RealSecure Network Sensor 5.5 Internet Security Systems RealSecure Network Sensor 5.0 Enterasys Dragon IDS 4.0 Cisco Secure IDS Network Sensor 3.0 Cisco Secure IDS Host Sensor 2.0 Cisco Catalyst 6000 IDS Module |
| Not Vulnerable: |
Snort Project Snort 1.8.1 Internet Security Systems RealSecure Server Sensor 6.0.1 Win Enterasys Dragon IDS 5.0 Computer Associates eTrust Intrusion Detection 1.5 Computer Associates eTrust Intrusion Detection 1.4.5 Cisco Secure IDS Network Sensor 3.0 (2)S6 |
Discussion
Multiple IDS Vendor Encoded IIS Attack Detection Evasion Vulnerability
The Microsoft IIS web server supports a non-standard method of encoding web requests. Because this method is non-standard, intrusion detection systems may not detect attacks encoded using this method.
This vulnerability only affects intrusion detection systems in environments where '%u' unicode encoding is supported by a webserver (ie, IIS). If there is no webserver support for this encoding method or if it is disabled, there will be no targets to which encoded attacks can be sent.
**NOTE**: Only RealSecure, Dragon and Snort are confirmed vulnerable. It is highly likely that IDS systems from other vendors are vulnerable as well, however we have not recieved confirmation. This record will be updated as more information becomes available regarding affected technologies.
BlackICE products detect '%u' encoded requests as being invalid, but do not decode them and detect encoded attack signatures.
The Microsoft IIS web server supports a non-standard method of encoding web requests. Because this method is non-standard, intrusion detection systems may not detect attacks encoded using this method.
This vulnerability only affects intrusion detection systems in environments where '%u' unicode encoding is supported by a webserver (ie, IIS). If there is no webserver support for this encoding method or if it is disabled, there will be no targets to which encoded attacks can be sent.
**NOTE**: Only RealSecure, Dragon and Snort are confirmed vulnerable. It is highly likely that IDS systems from other vendors are vulnerable as well, however we have not recieved confirmation. This record will be updated as more information becomes available regarding affected technologies.
BlackICE products detect '%u' encoded requests as being invalid, but do not decode them and detect encoded attack signatures.
Solution / Fix
Multiple IDS Vendor Encoded IIS Attack Detection Evasion Vulnerability
Solution:
Snort 1.8.1 has fixed this vulnerability.
ISS has released a fixed upgrade for the Windows RealSecure Server Sensor 6.0 and a patch for version 5.5. Administrators are advised to upgrade to version 6.0.1. ISS has also released a hotfix for RealSecure Network Sensor versions 5.x to 6.0.
Users of Dragon IDS are advised to upgrade to version 5.0, which is not vulnerable.
Cisco has released a fix for Secure IDS.
Snort Project Snort 1.5
Snort Project Snort 1.5.1
Snort Project Snort 1.5.2
Snort Project Snort 1.6
Snort Project Snort 1.6.1
Snort Project Snort 1.6.2
Snort Project Snort 1.6.3
Snort Project Snort 1.7
Snort Project Snort 1.8
Cisco Secure IDS Host Sensor 2.0
Cisco Secure IDS Network Sensor 3.0
Enterasys Dragon IDS 4.0
Internet Security Systems RealSecure Network Sensor 5.0
Internet Security Systems RealSecure Server Sensor 5.0 Win
Internet Security Systems RealSecure Server Sensor 5.5 Win
Internet Security Systems RealSecure Network Sensor 5.5
Internet Security Systems RealSecure Network Sensor 5.5.1
Internet Security Systems RealSecure Server Sensor 5.5.1 Win
Internet Security Systems RealSecure Network Sensor 5.5.2
Internet Security Systems RealSecure Server Sensor 5.5.2 Win
Internet Security Systems RealSecure Server Sensor 6.0 Win
Internet Security Systems RealSecure Network Sensor 6.0
Solution:
Snort 1.8.1 has fixed this vulnerability.
ISS has released a fixed upgrade for the Windows RealSecure Server Sensor 6.0 and a patch for version 5.5. Administrators are advised to upgrade to version 6.0.1. ISS has also released a hotfix for RealSecure Network Sensor versions 5.x to 6.0.
Users of Dragon IDS are advised to upgrade to version 5.0, which is not vulnerable.
Cisco has released a fix for Secure IDS.
Snort Project Snort 1.5
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.5.1
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.5.2
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6.1
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6.2
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6.3
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.7
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.8
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Cisco Secure IDS Host Sensor 2.0
-
Cisco Secure IDS Host Sensor 3.0(2)S6
ftp://ftp-eng.cisco.com/csids-sig-updates/ServicePacks/IDSk9-sp-3.0-1. 43-S6-0.43-.bin
Cisco Secure IDS Network Sensor 3.0
-
Cisco Secure IDS Host Sensor 3.0(2)S6
ftp://ftp-eng.cisco.com/csids-sig-updates/ServicePacks/IDSk9-sp-3.0-1. 43-S6-0.43-.bin
Enterasys Dragon IDS 4.0
-
Enterasys Dragon IDS 5.0
http://dragon.enterasys.com
Internet Security Systems RealSecure Network Sensor 5.0
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Server Sensor 5.0 Win
Internet Security Systems RealSecure Server Sensor 5.5 Win
-
Internet Security Systems RealSecure Server Sensor Patch
http://www.iss.net/eval/eval.php -
Internet Security Systems RealSecure Server Sensor 6.0.1 Win
Internet Security Systems RealSecure Network Sensor 5.5
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Network Sensor 5.5.1
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Server Sensor 5.5.1 Win
-
Internet Security Systems RealSecure Server Sensor Patch
http://www.iss.net/eval/eval.php -
Internet Security Systems RealSecure Server Sensor 6.0.1 Win
Internet Security Systems RealSecure Network Sensor 5.5.2
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Server Sensor 5.5.2 Win
Internet Security Systems RealSecure Server Sensor 6.0 Win
Internet Security Systems RealSecure Network Sensor 6.0
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
References
Multiple IDS Vendor Encoded IIS Attack Detection Evasion Vulnerability
References:
References:
- Cisco Sec Adv: Cisco Secure Intrusion Detection System Signature Obfuscation (Cisco)
- Dragon IDS Homepage (Enterasys)
- eEye Digital Security Team Home Page (eEye)
- Intrusion Detection Product Homepage (Internet Security Systems)
- NID Homepage (NFR)
- Secure Intrusion Detection Homepage (Cisco Systems)
- Snort Homepage (Martin Roesch)
- X-Force Web Page (Internet Security Systems)