|Check Point Reference:||SBP-2010-26|
|Date Published:||19 Sep 2010|
|Last Updated:||25 Jul 2017|
|Protection Provided by:||
|Who is Vulnerable?|
|Vulnerability Description||ASP.NET is a collection of technologies within the.NET Framework that enable developers to build Web applications and XML Web Services. A remote attacker may exploit this issue to read data, such as the View State, which was encrypted by the server.This vulnerability is caused by ASP.NET providing Web clients details in error messages when decrypting certain ciphertext. This is known as a "padding oracle" attack. Successful exploitation of this vulnerability could allow the attacker to read and tamper with data. If tampered with, the attacker could send this data back to the server and observe the error codes returned by the server. By observing these error codes, an attacker could gain enough information to decrypt and tamper with the encrypted data. There are cases in which certain traffic, although not intended for malicious use, is very unsafe, since it may transfer shellcode which is undetectable by IPS.|
This protection will detect and block multiple HTTP error responses.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update.For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Web Server Enforcement Violation.
Attack Information: Multiple HTTP Error Responses