NetScreen恶意URL过滤功能可绕过漏洞发布时间:2002-11-25 更新时间:2002-11-25 严重程度:中 威胁程度:其它 错误类型:意外情况处置错误 利用方式:服务器模式 BUGTRAQ ID:6254 受影响系统 NetScreen ScreenOS 3.1.1r2详细描述 NetScreen为了响应红色代码事件,增加了防火墙功能,可以防止访问外部恶意WEB服务器。这个功能设计可用于管理员快速限制访问WEB内容。 其中'Malicious-URL'阻挡实现存在漏洞,可以允许HTTP客户端绕过防火墙检测,访问受限制URL,通过把HTTP头中的URL分片到多个IP包中,可以绕过这个限制。 测试代码 尚无 解决方案 升级程序: NetScreen ScreenOS 3.1.1r2: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.1.0r9: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.1.0r2: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.1.0r1: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.1.0: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.0r4: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.0r3: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.0r2: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.0r1: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.0: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 2.8.0r1: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 2.7.1 r3: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 2.7.1 r2: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 2.7.1 r1: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 2.7.1: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.1 r2: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 3.0.1 r1: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp NetScreen ScreenOS 4.0: NetScreen Upgrade ScreenOS 4.0.1 http://www.netscreen.com/support/updates.asp 相关信息 "zel" <zel@firewallmonkeys.com>. 参考:http://www.netscreen.com/support/alerts/malicious_URL.html http://online.securityfocus.com/archive/1/300959 相关主页:http://www.netscreen.com/index.html |