SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#548515

Multiple intrusion detection systems may be circumvented via %u encoding

Overview

Multiple intrusion detection systems may be circumvented via %u encoding allowing intruders to launch attacks undetected.

I. Description

Most intrusion detection systems are capable of decoding URLs that are encoded using either the "UTF" or "hex-encode" encoding schemes. Microsoft's Information Server (IIS) employs both of these encoding schemes. It also makes use of an encoding scheme known as "%u encoding". According to the eEye Digital Security Advisory, "The purpose of this %u encoding seems to be for the ability to represent true Unicode/wide character strings." Because "%u encoding does not appear to be widely utilized by products other than Microsoft's Information Server (IIS), certain intrusion detection systems are not able to properly decode %u encoded requests.

II. Impact

An intruder can pass %u encoded malicious traffic undetected through an intrusion detection system in violation of implied security policies. This will typically be reconnaissance traffic and/or attack traffic directed at an IIS web server.

III. Solution

Contact your vendor for patches.

Systems Affected

VendorStatusDate NotifiedDate Updated
Cisco Systems Inc.Vulnerable7-Sep-2001
Enterasys NetworksVulnerable7-Sep-2001
Internet Security Systems Inc.Vulnerable7-Sep-2001
The Snort ProjectVulnerable18-Sep-2002

References


http://www.securityfocus.com/bid/3292
http://www.eeye.com/html/Research/Advisories/index.html
http://www.iss.net/db_data/xpu/RS.php
http://www.iss.net/eval/eval.php
http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml

Credit

The CERT Coordination Center thanks eEye Digital Security for their advisory, on which this document is based.

This document was written by Ian A. Finlay.

Other Information

Date Public:2001-09-05
Date First Published:2001-09-07
Date Last Updated:2003-10-30
CERT Advisory: 
CVE-ID(s):CAN-2001-0669
NVD-ID(s):CAN-2001-0669
US-CERT Technical Alerts: 
Metric:13.13
Document Revision:47

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader