BetaONE will rise again!


Reply
  #1  
Old 16th May 07, 02:53 AM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 30,903
NewsBot will become famous soon enough
Critical Unicode Flaw Undercuts Firewalls, Scanners
The U.S. Computer Emergency Response Team is reporting a network evasion technique that uses full-width and half-width unicode characters to allow malware to evade detection by an intrusion prevention system or firewall. The vulnerability concerns HTTP content-scanning systems that fail to properly scan full-width and half-width Unicode-encoded HTTP traffic. A remote attacker could exploit the vulnerability by sending specially crafted HTTP traffic to a vulnerable content scanning system. After sneaking under the firewall or IPS, the attacker can then scan and attack systems without being detected.

Multiple Cisco Systems products are affected, including Cisco's IPS CSCsi58602 and its Cisco IOS with Firewall/IPS Feature Set CSCsi67763. Cisco has an advisory up. In the advisory the company states that it's not aware of any exploits of the vulnerability. While Cisco is the only vendor to have verified that its products are vulnerable, there's a long list of vendors that haven't said whether their products are vulnerable or not. Specifically, the US-CERT note lists 92 vendors whose security products may be vulnerable; of those, as of the afternoon of May 15, only two-Apple and Hewlett-Packard-had verified that their security software isn't vulnerable.

View: Full Story
News source: eWeek

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Extremely Critical Flaw Discovered In Excel NewsBot NeoWin News 0 16th Jun 06 05:30 PM
Critical Flaw Discovered in Symantec AntiVirus Products NewsBot NeoWin News 0 26th May 06 05:30 PM
Missing parenthesis causes 'critical' *nix flaw NewsBot NeoWin News 0 3rd May 06 11:30 PM
Critical Flaw found in Winamp 5.06 and earlier NewsBot NeoWin News 0 28th Nov 04 07:00 AM


All times are GMT +1. The time now is 06:42 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.