多个IDS供应商编码IIS攻击侦查逃避漏洞

漏洞信息详情

多个IDS供应商编码IIS攻击侦查逃避漏洞

漏洞简介

含Windows的(1)Cisco Secure Intrusion Detection System,(2)Cisco Catalyst 6000 Intrusion Detection System Module,(3)Dragon Sensor 4.x版本,(4)Snort 1.8.1之前版本,(5)ISS RealSecure Network Sensor 5.x版本和6.x版本 XPU 3.2之前版本,以及(6)ISS RealSecure Server Sensor 5.5版本和6.0版本的各种的Intrusion Detection Systems (IDS)存在漏洞。远程攻击者可以借助要求的URL中ASCII字符的不标准\”\\%u\” Unicode编码逃避HTTP的侦查。

漏洞公告

Snort 1.8.1 has fixed this vulnerability.
ISS has released a fixed upgrade for the Windows RealSecure Server Sensor 6.0 and a patch for version 5.5. Administrators are advised to upgrade to version 6.0.1. ISS has also released a hotfix for RealSecure Network Sensor versions 5.x to 6.0.
Users of Dragon IDS are advised to upgrade to version 5.0, which is not vulnerable.
Cisco has released a fix for Secure IDS.
Snort Project Snort 1.5

Snort Project Snort 1.5.1

Snort Project Snort 1.5.2

Snort Project Snort 1.6

Snort Project Snort 1.6.1

Snort Project Snort 1.6.2

Snort Project Snort 1.6.3

Snort Project Snort 1.7

Snort Project Snort 1.8

Cisco Secure IDS Host Sensor 2.0

Cisco Secure IDS Network Sensor 3.0

Enterasys Dragon IDS 4.0

Internet Security Systems RealSecure Network Sensor 5.0

Internet Security Systems RealSecure Server Sensor 5.0 Win

  • Internet Security Systems RealSecure Server Sensor 6.0.1 Win

Internet Security Systems RealSecure Server Sensor 5.5 Win

Internet Security Systems RealSecure Network Sensor 5.5

Internet Security Systems RealSecure Network Sensor 5.5.1

Internet Security Systems RealSecure Server Sensor 5.5.1 Win

Internet Security Systems RealSecure Network Sensor 5.5.2

Internet Security Systems RealSecure Server Sensor 5.5.2 Win

  • Internet Security Systems RealSecure Server Sensor 6.0.1 Win

Internet Security Systems RealSecure Server Sensor 6.0 Win

  • Internet Security Systems RealSecure Server Sensor 6.0.1 Win

Internet Security Systems RealSecure Network Sensor 6.0

参考网址

来源:US-CERT Vulnerability Note: VU#548515
名称: VU#548515
链接:http://www.kb.cert.org/vuls/id/548515

来源: ISS
名称: 20010905 Multiple Vendor IDS Unicode Bypass Vulnerability
链接:http://xforce.iss.net/alerts/advise95.php

来源: CISCO
名称: 20010905 Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability
链接:http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml

来源: BUGTRAQ
名称: 20010905 %u encoding IDS bypass vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=99972950200602&w=2

来源: BID
名称: 3292
链接:http://www.securityfocus.com/bid/3292

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享