漏洞信息详情
多个IDS供应商编码IIS攻击侦查逃避漏洞
- CNNVD编号:CNNVD-200110-136
- 危害等级: 高危
- CVE编号:
CVE-2001-0669
- 漏洞类型:
环境条件错误
- 发布时间:
2001-10-30
- 威胁类型:
远程
- 更新时间:
2006-08-22
- 厂 商:
iss - 漏洞来源:
Credited to ‘hsj’ … -
漏洞简介
含Windows的(1)Cisco Secure Intrusion Detection System,(2)Cisco Catalyst 6000 Intrusion Detection System Module,(3)Dragon Sensor 4.x版本,(4)Snort 1.8.1之前版本,(5)ISS RealSecure Network Sensor 5.x版本和6.x版本 XPU 3.2之前版本,以及(6)ISS RealSecure Server Sensor 5.5版本和6.0版本的各种的Intrusion Detection Systems (IDS)存在漏洞。远程攻击者可以借助要求的URL中ASCII字符的不标准\”\\%u\” Unicode编码逃避HTTP的侦查。
漏洞公告
Snort 1.8.1 has fixed this vulnerability.
ISS has released a fixed upgrade for the Windows RealSecure Server Sensor 6.0 and a patch for version 5.5. Administrators are advised to upgrade to version 6.0.1. ISS has also released a hotfix for RealSecure Network Sensor versions 5.x to 6.0.
Users of Dragon IDS are advised to upgrade to version 5.0, which is not vulnerable.
Cisco has released a fix for Secure IDS.
Snort Project Snort 1.5
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.5.1
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.5.2
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6.1
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6.2
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.6.3
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.7
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Snort Project Snort 1.8
-
Martin Roesch snort-1.8.1-RELEASE.tar.gz
http://www.snort.org/releases/snort-1.8.1-RELEASE.tar.gz
Cisco Secure IDS Host Sensor 2.0
-
Cisco Secure IDS Host Sensor 3.0(2)S6
ftp://ftp-eng.cisco.com/csids-sig-updates/ServicePacks/IDSk9-sp-3.0-1.
43-S6-0.43-.bin
Cisco Secure IDS Network Sensor 3.0
-
Cisco Secure IDS Host Sensor 3.0(2)S6
ftp://ftp-eng.cisco.com/csids-sig-updates/ServicePacks/IDSk9-sp-3.0-1.
43-S6-0.43-.bin
Enterasys Dragon IDS 4.0
-
Enterasys Dragon IDS 5.0
http://dragon.enterasys.com
Internet Security Systems RealSecure Network Sensor 5.0
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Server Sensor 5.0 Win
Internet Security Systems RealSecure Server Sensor 5.5 Win
-
Internet Security Systems RealSecure Server Sensor Patch
http://www.iss.net/eval/eval.php -
Internet Security Systems RealSecure Server Sensor 6.0.1 Win
Internet Security Systems RealSecure Network Sensor 5.5
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Network Sensor 5.5.1
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Server Sensor 5.5.1 Win
-
Internet Security Systems RealSecure Server Sensor Patch
http://www.iss.net/eval/eval.php -
Internet Security Systems RealSecure Server Sensor 6.0.1 Win
Internet Security Systems RealSecure Network Sensor 5.5.2
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
Internet Security Systems RealSecure Server Sensor 5.5.2 Win
Internet Security Systems RealSecure Server Sensor 6.0 Win
Internet Security Systems RealSecure Network Sensor 6.0
-
Internet Security Systems XPU 3.2
http://www.iss.net/db_data/xpu/RSNS 3.2.php
参考网址
来源:US-CERT Vulnerability Note: VU#548515
名称: VU#548515
链接:http://www.kb.cert.org/vuls/id/548515
来源: ISS
名称: 20010905 Multiple Vendor IDS Unicode Bypass Vulnerability
链接:http://xforce.iss.net/alerts/advise95.php
来源: CISCO
名称: 20010905 Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability
链接:http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml
来源: BUGTRAQ
名称: 20010905 %u encoding IDS bypass vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=99972950200602&w=2
来源: BID
名称: 3292
链接:http://www.securityfocus.com/bid/3292