Finjan SurfinGate Active Content Filter Bypass Vulnerability
BID:6701
Info
Finjan SurfinGate Active Content Filter Bypass Vulnerability
| Bugtraq ID: | 6701 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2003 12:00AM |
| Updated: | Jan 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Compass Security. |
| Vulnerable: |
Finjan Software SurfinGate 5.6 |
| Not Vulnerable: |
Finjan Software SurfinShield Corporate 5.7 Finjan Software SurfinGate 6.0 5 Finjan Software SurfinGate 6.0 1 Finjan Software SurfinGate 6.0 |
Discussion
Finjan SurfinGate Active Content Filter Bypass Vulnerability
A flaw was reported in the JavaScript parser included with the Finjan SurfinGate active content filter. The JavaScript parser does not sufficiently sanitize script code.
It is possible to bypass the filter by obfuscating the malicious JavaScript. This may be accomplished by hex-encoding the malicious code and then passing it through a function which decodes the string (such as through the eval() method).
The desktop product, Finjan SurfinShield Corporate, is not prone to this issue. Finjan also reportedly offers a free service which allows users to add custom triggers for script functions.
A flaw was reported in the JavaScript parser included with the Finjan SurfinGate active content filter. The JavaScript parser does not sufficiently sanitize script code.
It is possible to bypass the filter by obfuscating the malicious JavaScript. This may be accomplished by hex-encoding the malicious code and then passing it through a function which decodes the string (such as through the eval() method).
The desktop product, Finjan SurfinShield Corporate, is not prone to this issue. Finjan also reportedly offers a free service which allows users to add custom triggers for script functions.
Exploit / POC
Finjan SurfinGate Active Content Filter Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Finjan SurfinGate Active Content Filter Bypass Vulnerability
Solution:
The vendor has addressed this issue in versions 6.0 and later of the software. However, it should be noted that other techniques for obfuscating JavaScript and other active content may exist which have not been addressed.
Solution:
The vendor has addressed this issue in versions 6.0 and later of the software. However, it should be noted that other techniques for obfuscating JavaScript and other active content may exist which have not been addressed.
References
Finjan SurfinGate Active Content Filter Bypass Vulnerability
References:
References:
- SurfinGate Product Page (Finjan Software)
- RE: Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate V5.6 ("Menashe Eliezer"
) - Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate v5.6 ("[email protected]"
)