exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

netgearURI.txt

netgearURI.txt
Posted May 25, 2004
Authored by Marc Ruef | Site computec.ch

Netgear RP114 devices, and possibly other related Netgear hardware, have a URI filtering bypass vulnerability when the URI being evaluated is larger than 220 bytes long.

tags | advisory, bypass
SHA-256 | 7c2791d42f4fe25ac35ea87b471ff12f43f5d2022deaf13d5ef51f4d2621d65f

netgearURI.txt

Change Mirror Download
Hi!

Netgear has some small router and firewalling devices for home users and
small companies (SOHO). Most of these solutions are able to do a simple
keyword based URL filtering. Lets say we don't want users to visit
http://www.scip.ch so we create a filter for the keyword "scip.ch". If a
user wants to access a domain that contains the string "scip.ch" (e.g.
www.scip.ch or test.scip.ch) he will get a white html document that says
"Blocked by NETGEAR". He is not able to see the requested document itself.

I found that my cute Netgear RP114 is not able to do the filtering if
the requested URI is more than 220 bytes long. Other Netgear routers and
firewalls may also be affected. If you are requesting the following URL,
you will be able to see the requested web document without restriction:

http://www.scip.ch/?%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20

(FYI: your mail client may break the URL into different lines)

An attacker may be able to evade the URL black list and get access to
disallowed ressources. This may be a buffer overflow and it may be
possible to run arbitrary code on the Netgear device. My open-source
Attack Tool Kit (ATK) provides a plugin to check this flaw. See
http://www.computec.ch/projekte/atk/ for more details.

There may be some problems for the attacker if he wants to access a
script (e.g. CGI) that has some problems with the argument after the
question mark. There may be also further problems if the web browser or
server does not allow URLs as long as the needed one.

Netgear may provide a new firmware or another workaround. But their
support is often lame and ignorant (my last few support questions were
be ignored as usual). I suggest to install another URL filtering
solution if this functionality is really needed.

An original copy of this posting can be found at
http://www.computec.ch/mruef/advisories/ - A description of this and
other vulnerabilities on german can be found in the scip Vulnerability
Database at http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=667

Yours, Marc Ruef

--
http://www.computec.ch
http://www.scip.ch

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    21 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close