|
|||||||||||
|
RE: TippingPoint IPS Signature Evasion
From: Paul Craig <paul.craig(at)security-assessment.com>
Date: Wed Jul 11 2007 - 16:44:26 EDT
I also agree with you, blaming an IPS for not detecting attack which is impossible in the wild would be very pointless. Although IIS 5 is old, it is still relatively common. Any further questions, feel free to ask. Cheers,
Paul Craig
-----Original Message----- Dear Paul Craig, --Wednesday, July 11, 2007, 1:37:03 AM, you wrote to PC> http://www.test.com/scripts%c0%afcmd.exe PC> http://www.test.com/scripts%e0%80%afcmd.exe PC> http://www.test.com/scripts%c1%9ccmd.exe PC> Web servers located behind a Tippingpoint IPS device which are capablePC> of decoding alternate Unicode characters can be accessed, and exploited PC> without triggering the IPS device. Can you, please, provide example of such server? Fatih Ozavci reported similar problem with Checkpoint and Halfwidth/Fullwidth Unicode, potential attack vector was IIS with .Net framework, in this case IIS seems not to be exploitable. Blaming IPS it does not detect attack which is impossible in-the-wild is nonsense. Blaming corporate-level IPS doesn't detect attack against SOHO web server is acceptable nonsense :) -- This archive was generated by hypermail 2.1.8 : Thu Aug 09 2007 - 17:55:45 EDT |
||||||||||
|
|||||||||||