
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 61
ISAServerVuln erabilities
AccordingtoSamCostelloofIDGNewsService,
“MicrosoftFriday(08/17/01) saidthatoneofitssecurityproducts,InternetSecurity
andAccelerationServer2000,hasthreedifferentsecurityholesthatcouldleadto
denialofserviceattacks.Microsofthasissuedapatchtofixallthree vulnerabilities.
TheflawsareunrelatedandaffectISAServer'sVoiceoverIPcapabilities,itsProxy
serviceandISA'serrorpagegeneration.Thefirstvulnerabilityconcernsamemory
leakintheH.323Gatekeeperservice,whichallowsvoiceoverIPtrafficthrougha
firewall.Eachtimemalformeddataissenttothisservice,asmallamountofthe
server'smemoryisdepleted,Microsoftsaid.Ifsuchrequestsaresentfrequently
enough,theserverwouldbesloweddowntothepointofdisruptingnormaluse.
Thisproblemismitigated,however,inthattheservercanonlybeattackedifthe
H.323Gatekeepercomponentisinstalled,somethingthatonlyhappenswhenauser
choosesa "fullinstallation,"ortoinstalleverythingonthesoftwareCDrelatedtothe
application.
ThesecondproblemISAServerfacesisadenialofserviceprobleminthesoftware's
Proxyservice.Thisflaw, likethefirst,isalsoamemoryleakthatcancauseaslowing
oftheserverandleadto denialofservicetolegitimateusers.Thisholeismadeless
seriousbecauseitcanonlybeexploitedbyaninternaluser,Microsoftsaid.
Lastly, acomplicatedvulnerabilityinthewayISAServerhandleserrormessages
aboutirretrievableWebpagescanallowanattackertoexecutecodeandgainaccess
tocookiesonboththeserverandusermachines.Theflawcouldbeexploitedifan
attackerwereablet otrickauserintorequestingaWeb pagethatdidnotresideona
server.ThefalseURLwouldalsohavetocontaincode.WhenISAServergeneratesan
errorpagestatingthattherequestedpageisnotavailable,thecodecontainedinthe
URLwouldrunintheserver'ssecuritydomainandanycookiesthatserverhadseton
theuser'ssystemwouldbeavailabletotheattacker.Thisvulnerabilityislimitedin
thattheattackerwouldhavetoknowwhichsitesausertrusted,whichsiteshad
placedcookiesontheuser'scomputerandthattheuserhadspecificsecuritysettings
thatwouldallowtheattack.
Kommentare zu diesen Handbüchern