what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

netgearURI.txt

netgearURI.txt
Posted May 25, 2004
Authored by Marc Ruef | Site computec.ch

Netgear RP114 devices, and possibly other related Netgear hardware, have a URI filtering bypass vulnerability when the URI being evaluated is larger than 220 bytes long.

tags | advisory, bypass
SHA-256 | 7c2791d42f4fe25ac35ea87b471ff12f43f5d2022deaf13d5ef51f4d2621d65f

netgearURI.txt

Change Mirror Download
Hi!

Netgear has some small router and firewalling devices for home users and
small companies (SOHO). Most of these solutions are able to do a simple
keyword based URL filtering. Lets say we don't want users to visit
http://www.scip.ch so we create a filter for the keyword "scip.ch". If a
user wants to access a domain that contains the string "scip.ch" (e.g.
www.scip.ch or test.scip.ch) he will get a white html document that says
"Blocked by NETGEAR". He is not able to see the requested document itself.

I found that my cute Netgear RP114 is not able to do the filtering if
the requested URI is more than 220 bytes long. Other Netgear routers and
firewalls may also be affected. If you are requesting the following URL,
you will be able to see the requested web document without restriction:

http://www.scip.ch/?%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20

(FYI: your mail client may break the URL into different lines)

An attacker may be able to evade the URL black list and get access to
disallowed ressources. This may be a buffer overflow and it may be
possible to run arbitrary code on the Netgear device. My open-source
Attack Tool Kit (ATK) provides a plugin to check this flaw. See
http://www.computec.ch/projekte/atk/ for more details.

There may be some problems for the attacker if he wants to access a
script (e.g. CGI) that has some problems with the argument after the
question mark. There may be also further problems if the web browser or
server does not allow URLs as long as the needed one.

Netgear may provide a new firmware or another workaround. But their
support is often lame and ignorant (my last few support questions were
be ignored as usual). I suggest to install another URL filtering
solution if this functionality is really needed.

An original copy of this posting can be found at
http://www.computec.ch/mruef/advisories/ - A description of this and
other vulnerabilities on german can be found in the scip Vulnerability
Database at http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=667

Yours, Marc Ruef

--
http://www.computec.ch
http://www.scip.ch

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close