OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA12749] ASP.NET Canonicalization Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Oct 08 2004 - 03:19:49 CDT


TITLE:
ASP.NET Canonicalization Vulnerability

SECUNIA ADVISORY ID:
SA12749

VERIFY ADVISORY:
http://secunia.com/advisories/12749/

CRITICAL:
Moderately critical

IMPACT:
Security Bypass

WHERE:
From remote

SOFTWARE:
Microsoft .NET Framework 1.x
http://secunia.com/product/667/
ASP.NET 1.x
http://secunia.com/product/2173/

DESCRIPTION:
Toby Beaumont has reported a vulnerability in ASP.NET, which can be
exploited by malicious people to bypass certain security
restrictions.

The vulnerability is caused due to a canonicalization error within
the .NET authentication schema. This can be exploited to bypass forms
based authentication or Windows authorization configurations by using
a specially crafted URL.

Example:
http://[victim]/secure%5Cfile.apx

Successful exploitation can e.g. lead to exposure of sensitive
information.

The vulnerability reportedly affects all versions of ASP.NET for all
versions of IIS.

SOLUTION:
Apply ASP.NET ValidatePath module.
http://www.microsoft.com/downloads/details.aspx?FamilyId=DA77B852-DFA0-4631-AAF9-8BCC6C743026

PROVIDED AND/OR DISCOVERED BY:
Toby Beaumont

ORIGINAL ADVISORY:
Microsoft:
http://www.microsoft.com/security/incident/aspnet.mspx
http://support.microsoft.com/?kbid=887459

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------