Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-sigs] ASP.net Auth Bypass Vulnerability |
|---|---|
| Date: | Thu, 07 Oct 2004 19:08:42 -0500 |
Maybe a within statement. Other ideas????
Matt
I think it is any file, but it has to be served up by the .NET ISAPI filter.. Sites running IIS without the .net isapi filter, appear to not be vulnerable to this..
This bugtraq post makes it sound as if you could hit any file:
http://www.derkeiler.com/Mailing-Lists/NT-Bugtraq/2004-09/0068.html
But... if we were just looking for a sig to find the initial wave of scripts that'll be probing for this they'll certainly try the default aspx stuff, that could be a good limiter on a sig for just that.
I'll make something like that and test it out real quick. Update from bleedingsnort.com in a few if you'd like to try it out as well.
Matt
sekure wrote:
Sounds to me like you have to be trying to access a .aspx file, so that could be something to look for. But I am just speculating here... Guess we have to wait for more info from MS.
On Thu, 07 Oct 2004 12:50:01 -0500, Matt Jonkman <matt@infotex.com> wrote:
http://isc.sans.org/diary.php?date=2004-10-06
This could be a big one. Anyone that understands asp.net better than I able to put up a sig?
Not sure on all of the permutations that this could manifest in.
Or could we safely just look for any \ or %5C in a url? How many other legitimate places would those arise?
What would be the default directories that the average server would have sensitive information in by default that someone might try getting to via canonicalization?
alert tcp any any -> $HOME_NET 80 (msg: BLEEDING-EDGE WEB-EXPLOIT ASP.net Auth Bypass / Canonicalization"; uricontent:"\"; sid:; rev:1;)
or
alert tcp any any -> $HOME_NET 80 (msg: BLEEDING-EDGE WEB-EXPLOIT ASP.net Auth Bypass / Canonicalization"; uricontent:"%5C"; sid:; rev:1;)
I think we need another factor to make this more specific though. Any ideas?
More discussion on www.bleedingsnort.com as well.
Matt
------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
-- -------------------------------------------- Matthew Jonkman, CISSP Senior Security Engineer Infotex 765-429-0398 Direct Anytime 765-448-6847 Office 866-679-5177 24x7 NOC my.infotex.com www.offsitefilter.com --------------------------------------------
NOTICE: The information contained in this email is confidential and intended solely for the intended recipient. Any use, distribution, transmittal or retransmittal of information contained in this email by persons who are not intended recipients may be a violation of law and is strictly prohibited. If you are not the intended recipient, please contact the sender and delete all copies.
------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
-- -------------------------------------------- Matthew Jonkman, CISSP Senior Security Engineer Infotex 765-429-0398 Direct Anytime 765-448-6847 Office 866-679-5177 24x7 NOC my.infotex.com www.offsitefilter.com --------------------------------------------
NOTICE: The information contained in this email is confidential and intended solely for the intended recipient. Any use, distribution, transmittal or retransmittal of information contained in this email by persons who are not intended recipients may be a violation of law and is strictly prohibited. If you are not the intended recipient, please contact the sender and delete all copies.
------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-sigs] ASP.net Auth Bypass Vulnerability, sam |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, matt |
| Previous by Thread: | Re: [Snort-sigs] ASP.net Auth Bypass Vulnerability, sam |
| Next by Thread: | [Snort-sigs] Classtype accuracy?, nnposter |
| Indexes: | [Date] [Thread] [Top] [All Lists] |