IPS-1 Protection Update for WWW2 (Version 27)
| Check Point Reference: | CPAI-2007-201 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | US-CERT Vulnerability Note VU#739224 |
|
| Industry Reference(s): | CVE-2007-2688 CVE-2007-3701 |
|
| Protection Provided by: |
IPS-1
|
|
| Who is Vulnerable? All IPS-1 products with versions of WWW2 prior to version 27 | ||
| Vulnerability Description Microsoft IIS decodes Unicode character sets in a variety of ways. There is an uncommon way of creating Unicode characters in HTTP, which IIS (but no other known web servers) decode. It is in the form of percent-u-hexchar-hexchar-hexchar-hexchar. The IPS-1 WWW2 protocol subsystem has been updated to take full advantage of the latest engine builtins to more properly handle some of the more esoteric Unicode evasion techniques (such as half-width/full-width encoding). |
||
|
Vulnerability Status N/A |
|
|
Update/Patch Available N/A |
|
|
Vulnerability Details Microsoft IIS decodes Unicode character sets in a variety of ways. There is an uncommon way of creating Unicode characters in HTTP, which IIS (but no other known web servers) decode. It is in the form of percent-u-hexchar-hexchar-hexchar-hexchar. The referenced character may be within the normal ASCII character set, and would be interpreted by the IIS server as such. Various intrusion detection systems will not appropriately decode this character into its native form, permitting attacks encoded in this manner to go undetected. So-called "half-width" and "full-width" Unicode encoding schemesare recognized in the form of %uff[hex char][hexchar]. |
Protection Overview
This update adds the capability of the web package to properly decode requests that implement normal unicode, and alert on anything that attempts to send an URI with half-width/full-width decoding.
The IPS-1 WWW2 protocol subsystem has been updated to take full advantage of the latest engine builtins to more properly handle some of the more esoteric Unicode evasion techniques (such as half-width/full-width encoding).
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
N/A