Latest news
March 26, 2003 - Corsaire, www.corsaire.com, an independent information security consultancy, have discovered an issue with the way Symantec Enterprise Firewall [1] handles URL encoding techniques causing pattern correlation evasion and in certain instances attacks to transpire.The Symantec Enterprise Firewall uses an application proxy strategy to provide enhanced security features for a variety of common protocols. For the HTTP proxy, part of this additional functionality allows the firewall to block URLs based on predefined regular expression patterns. However, by using URL encoding techniques this pattern matching functionality can easily be evaded.
The HTTP pattern matching functionality works by analysing the HTTP URL format and comparing these against a database of predefined signatures. When an HTTP connection is passed via a rule that is configured to use the pattern matching functionality, it is checked against the signature database and if a match is found, the request is blocked with a 403 Forbidden error.
Martin O'Neal, Technical Director at Corsaire warns, " if one of the standard URL encoding techniques (e.g. escaped encoding, Unicode, UTF-8) is used then the pattern matching will fail to trigger, and the attack will succeed. Consequentially, we notified our client base (without exposing any of the details) and passed a full advisory onto Symantec for resolution."
To minimize the risks associated with URL buffer overflow techniques, Symantec have recommended that web servers be regularly patched in accordance with the vendor's latest specifications. Further information is available at http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754
References
[1] www.symantec.com
About Corsaire
With over 6 years experience in providing network security solutions to the private, public and non-profit sectors, including the FTSE 100, Corsaire is considered the UK's leading specialist in the delivery of information security design, implementation and management. Whilst offering a broad range of bespoke solutions that are based on industry standards & guidelines, Corsaire adopt a consultative approach and combine a vendor neutral policy with knowledge-share to deliver impartial, up-to-date, personable advice. Corsaire is respected for its contribution to R&D, its consistent, high-level service delivery and an ability to combine technical and commercial excellence within the workplace.


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





