[NT] Microsoft ISA Server 2004 Log Manipulation



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Microsoft ISA Server 2004 Log Manipulation
------------------------------------------------------------------------


SUMMARY

" <http://www.microsoft.com/isaserver/default.mspx> Microsoft Internet
Security and Acceleration (ISA) Server 2004 is the advanced stateful
packet and application-layer inspection firewall, virtual private network
(VPN), and Web cache solution that enables enterprise customers to easily
maximize existing information technology (IT) investments by improving
network security and performance."

There is a Log Manipulation vulnerability in Microsoft ISA Server 2004,
which when exploited will enable a malicious user to manipulate the
Destination Host parameter of the log file.

DETAILS

Vulnerable Systems:
* Microsoft ISA Server 2004

By sending the following request to the server:
GET / HTTP/1.0
Host: %01%02%03%04
Transfer-Encoding: whatever

We were able to insert arbitrary characters, in this case the ASCII
characters 1, 2, 3 (respectively) into the Destination Host parameter of
the log file.

This has been found after 3 days of running the beSTORM fuzzer at 600+
Sessions per Second while monitoring the ISA Server log file for problems.

Vendor response:
"Microsoft does not consider this issue to be a security vulnerability."

Disclosure Timeline:
Reported to vendor: December, 2005
Public release date: 4th of May, 2006


ADDITIONAL INFORMATION

The information has been provided by Noam Rathaus using the beSTORM
fuzzer.
The original article can be found at:
<http://www.beyondsecurity.com/besirt/advisories/042006-001-ISA-LM.txt>
http://www.beyondsecurity.com/besirt/advisories/042006-001-ISA-LM.txt



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • IPSEC through Ms ISA Server
    ... Is it possible to have a third party IPSEC client to go through a Microsoft ISA server. ... I can't see any default packet filter or rule to set. ... prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
    (Focus-Microsoft)
  • SV: services running in windows domain (winXP clients)
    ... effectiveness of logon scripts as a security check/enforcement mechanism. ... FileName specifies a new database, ... Specifies the path and file name of the log file for the process. ...
    (Focus-Microsoft)
  • Re: MS Security Configuration Tool Set (SCTS)
    ... Security or Edit Security to see the current setting and the proposed new ... It looks like if and when the policy template is actually applied, ... > The log file goes into %systemroot%\security\logs by default. ... >>I think these tools will only let you compare a template with the ...
    (microsoft.public.security)
  • Re: Remove GP from machine that has been removed from AD
    ... Location of the log file - %windir%\security\logs ... Execute a gpupdate /force, verify you get the 1202 event, and post the log ... CCNA, MCSE 2000/2003 + Security ... My machine took the normal> Group Policy. ...
    (microsoft.public.windows.group_policy)
  • Re: AspErrorsToNTLog no longer works in IIS6
    ... Am I to assume IIS6 no longer offers a way to audit VBScript errors? ... >>when the security log is full has any relevance. ... Is event log performance significantly ... > log instead of the normal log file) was flawed from a security perspective, ...
    (microsoft.public.inetserver.iis)