Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

IPS-1 Protection Update for WWW2 (Version 27)

Subscribe

Check Point Reference: CPAI-2007-201
Date Published:
Severity:
Last Updated:
Source:

US-CERT Vulnerability Note VU#739224

Industry Reference(s): CVE-2007-2688
CVE-2007-3701
Protection Provided by: IPS-1
  • IPS-1
Who is Vulnerable?
All IPS-1 products with versions of WWW2 prior to version 27
Vulnerability Description

Microsoft IIS decodes Unicode character sets in a variety of ways. There is an uncommon way of creating Unicode characters in HTTP, which IIS (but no other known web servers) decode. It is in the form of percent-u-hexchar-hexchar-hexchar-hexchar.

The IPS-1 WWW2 protocol subsystem has been updated to take full advantage of the latest engine builtins to more properly handle some of the more esoteric Unicode evasion techniques (such as half-width/full-width encoding).

Vulnerability Status
N/A
Update/Patch Available
N/A
Vulnerability Details

Microsoft IIS decodes Unicode character sets in a variety of ways. There is an uncommon way of creating Unicode characters in HTTP, which IIS (but no other known web servers) decode. It is in the form of percent-u-hexchar-hexchar-hexchar-hexchar.

The referenced character may be within the normal ASCII character set, and would be interpreted by the IIS server as such. Various intrusion detection systems will not appropriately decode this character into its native form, permitting attacks encoded in this manner to go undetected.

So-called "half-width" and "full-width" Unicode encoding schemesare recognized in the form of %uff[hex char][hexchar].

Protection Overview

This update adds the capability of the web package to properly decode requests that implement normal unicode, and alert on anything that attempts to send an URI with half-width/full-width decoding.

The IPS-1 WWW2 protocol subsystem has been updated to take full advantage of the latest engine builtins to more properly handle some of the more esoteric Unicode evasion techniques (such as half-width/full-width encoding).

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
N/A

IPS-1

How Can I Protect My Network?
Ensure that all the latest signature updates from the SmartDefense Research team are installed on the IPS-1 sensor.

How Do I Know if My Network is Under Attack?
Any alerts in the form of www2_iis:percentu_alert should be investigated as potential attempts to bypass the IPS-1 device.