xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

NetScreen恶意URL过滤功能可绕过漏洞


发布时间:2002-11-25
更新时间:2002-11-25
严重程度:
威胁程度:其它
错误类型:意外情况处置错误
利用方式:服务器模式

BUGTRAQ ID:6254

受影响系统
NetScreen ScreenOS 3.1.1r2
NetScreen ScreenOS 3.1.0r9
NetScreen ScreenOS 3.1.0r2
NetScreen ScreenOS 3.1.0r1
NetScreen ScreenOS 3.1.0
NetScreen ScreenOS 3.0.0r4
NetScreen ScreenOS 3.0.0r3
NetScreen ScreenOS 3.0.0r2
NetScreen ScreenOS 3.0.0r1
NetScreen ScreenOS 3.0.0
NetScreen ScreenOS 2.8.0r1
NetScreen ScreenOS 2.7.1 r3
NetScreen ScreenOS 2.7.1 r2
NetScreen ScreenOS 2.7.1 r1
NetScreen ScreenOS 2.7.1
NetScreen ScreenOS 3.0.1 r2
NetScreen ScreenOS 3.0.1 r1
NetScreen ScreenOS 4.0
详细描述
NetScreen为了响应红色代码事件,增加了防火墙功能,可以防止访问外部恶意WEB服务器。这个功能设计可用于管理员快速限制访问WEB内容。

其中'Malicious-URL'阻挡实现存在漏洞,可以允许HTTP客户端绕过防火墙检测,访问受限制URL,通过把HTTP头中的URL分片到多个IP包中,可以绕过这个限制。

测试代码
尚无

解决方案
升级程序:

NetScreen ScreenOS 3.1.1r2:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.1.0r9:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.1.0r2:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.1.0r1:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.1.0:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.0r4:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.0r3:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.0r2:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.0r1:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.0:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 2.8.0r1:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 2.7.1 r3:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 2.7.1 r2:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 2.7.1 r1:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 2.7.1:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.1 r2:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 3.0.1 r1:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

NetScreen ScreenOS 4.0:

NetScreen Upgrade ScreenOS 4.0.1
http://www.netscreen.com/support/updates.asp

相关信息
"zel" <zel@firewallmonkeys.com>.
参考:http://www.netscreen.com/support/alerts/malicious_URL.html
http://online.securityfocus.com/archive/1/300959
相关主页:http://www.netscreen.com/index.html