FW: MS04-11, SSL, and ISA Server

From: Kim, Cameron (CKim_at_MDEA.COM)
Date: 05/04/04

  • Next message: Javier Fernandez-Sanguino: "Re: New LSASS-based worm finally here (Sasser)"
    Date:         Tue, 4 May 2004 10:16:14 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    I found this response to be very interesting. Thought people might want
    to know.

    Cameron Kim
    Mitsubishi Digital Electronics America

    -----Original Message-----
    From: Kayne Ian (Softlab) [mailto:Ian.Kayne@softlab.co.uk]
    Sent: Tuesday, May 04, 2004 3:42 AM
    To: Kim, Cameron
    Subject: RE: MS04-11, SSL, and ISA Server

    Yes, it is vulnerable in every scenario. I've personally verified this
    using the remote shell exploit floating around. In one of the MS
    bulletins they state that ISA can prevent this vuln when all packet
    filters are enabled - I found this NOT to be true. ISA remained
    vulnerable. After the patch is installed, ISA starts logging SChannel
    errors when the vuln is attempted to be exploited.

    HTH.

    > -----Original Message-----
    > From: Kim, Cameron [mailto:CKim@MDEA.COM]
    > Sent: 29 April 2004 02:12
    > To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    > Subject: MS04-11, SSL, and ISA Server
    >
    >
    > Can this DoS be performed against an ISA server which proxies the SSL
    > connections? Most of the reports and comments have mentioned the fact
    > that DoS can be performed against IIS servers using SSL connections.
    > But I am not sure if the ISA Server 2000 web proxy actually uses the
    > Microsoft SSL Library. One would suppose so...
    >
    > Cameron Kim
    > Mitsubishi Digital Electronics America
    >
    > -----
    > Earn up to 10 credit course hours toward the TruSecure ICSA
    > Practitioner (TICSA) Credential and receive a TICSA exam coupon by
    > attending the Infosecurity Canada 2004 conference.
    > Featured speaker, Marcus J. Ranum, TruSecure inventor of the proxy
    > firewall will present on June 3 at 11:30 AM. Visit
    <https://ticsa.trusecure.com> for certification details and
    <http://www.infosecuritycanada.com> for conference information. Become
    TICSA certified and see what happens!
    -----

    ********************************************************************
    This email and any files transmitted with it are confidential and
    intended solely for the use of the individual or entity to whom they are
    addressed.

    If you are not the intended recipient or the person responsible for
    delivering to the intended recipient, be advised that you have received
    this email in error and that any use of the information contained within
    this email or attachments is strictly prohibited.

    Internet communications are not secure and Softlab does not accept any
    legal responsibility for the content of this message. Any opinions
    expressed in the email are those of the individual and not necessarily
    those of the Company.

    If you have received this email in error, or if you are concerned with
    the content of this email please notify the IT helpdesk by telephone on
    +44 (0)121 788 5480.

    ********************************************************************

    -----
    Earn up to 10 credit course hours toward the TruSecure ICSA Practitioner (TICSA) Credential and receive a TICSA exam coupon by attending the Infosecurity Canada 2004 conference. Featured speaker, Marcus J. Ranum, TruSecure inventor of the proxy firewall will present on June 3 at 11:30 AM. Visit <https://ticsa.trusecure.com> for certification details and <http://www.infosecuritycanada.com> for conference information. Become TICSA certified and see what happens!
    -----


  • Next message: Javier Fernandez-Sanguino: "Re: New LSASS-based worm finally here (Sasser)"

    Relevant Pages

    • Re: SSL VPN appliance vs ISA server
      ... If you have the opportunity to use IAG then do it. ... I disagree with the term SSL VPN,...it may be SSL but there is nothing "VPN" ... Microsoft ISA Server Partners: Partner Hardware Solutions ... points to using a reverse proxy like ISA server or a SSL VPN appliance to ...
      (microsoft.public.isa.configuration)
    • RE: ISA 2006 and SSL
      ... In ISA Server 2006, SSL bridging is automatically configured when the ... A client requests an SSL object. ... The Web server returns the HTTP object to ...
      (microsoft.public.isa)
    • Re: ISA - IIS - SSL question
      ... > IIS. ... Enabled SSL Listeners on ISA server for our public IP ... > that is made available to the internet by a device other than your ISA ...
      (microsoft.public.isaserver)
    • Re: ISA wildcard certificate
      ... | I'm having trouble to configure my setup with a wildcard SSL. ... The subject of the certificate presented to the webclient from ISA MUST be ... The subject of the certificate presented to the ISA server from IIS MUST be ...
      (microsoft.public.isa)
    • Re: SP2 Problem
      ... ISA Server was unable to decompress a response body from /servlets because ... see Help and Support Center at ... you could try disabling the 2 compression web ...
      (microsoft.public.isa)