• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1807
  • Last Modified:

ValidateRequest filters asp.net pegged as vulnerable by Qualys scan

We have an internal Qualys scanner that is pegging an ASP.NET ValidateRequest filters Bypass Cross-Site scripting vulnerability on an Exchange 2003 SP2 OWA box running Windows Server 2003 SP2.  The Qualys report indicates no patch is available for this specific issue, but I was wondering if I needed to update the ASP.NET on the system. ASP.NET is at version 1.1.4322, but I was unsure if it was upgradeable on Windows server 2003 since we have .NET 3.5 SP1 installed.

Anyone have any idea on this particular issue OR on upgrading ASP.NET please feel free to comment. Thanks.
0
dumamo
Asked:
dumamo
1 Solution
 
ahoffmannCommented:
sounds like the same problem as described in http://www.experts-exchange.com/Q_27656217.html
except that you use :net 1.x; not sure if a fix will be available for that
if there is no fix, you either need to fix the application, or install a WAF (modsecuity on apache may help)
0
 
pand0ra_usaCommented:
Have you applied KB931832 and KB950159?

If you are not already using URLScan from Microsoft (ISAPI filter) you should look at installing it.

Here is a paper discussing that type of attack (so you have a better understanding of it and some examples you can use to validate if you are vulnerable - don't blindly trust Qualys or any scanner. Verifiy the results):
http://www.procheckup.com/vulnerability_manager/documents/document_1258758664/bypassing-dot-NET-ValidateRequest.pdf

http://technet.microsoft.com/en-us/security/bulletin/ms07-040
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Microsoft Office 2010

This course will introduce you to the interfaces and features of Microsoft Office 2010 Word, Excel, PowerPoint, Outlook, and Access. You will learn about the features that are shared between all products in the Office suite, as well as the new features that are product specific.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now