Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1790
  • Last Modified:

ValidateRequest filters asp.net pegged as vulnerable by Qualys scan

We have an internal Qualys scanner that is pegging an ASP.NET ValidateRequest filters Bypass Cross-Site scripting vulnerability on an Exchange 2003 SP2 OWA box running Windows Server 2003 SP2.  The Qualys report indicates no patch is available for this specific issue, but I was wondering if I needed to update the ASP.NET on the system. ASP.NET is at version 1.1.4322, but I was unsure if it was upgradeable on Windows server 2003 since we have .NET 3.5 SP1 installed.

Anyone have any idea on this particular issue OR on upgrading ASP.NET please feel free to comment. Thanks.
0
dumamo
Asked:
dumamo
1 Solution
 
ahoffmannCommented:
sounds like the same problem as described in http://www.experts-exchange.com/Q_27656217.html
except that you use :net 1.x; not sure if a fix will be available for that
if there is no fix, you either need to fix the application, or install a WAF (modsecuity on apache may help)
0
 
pand0ra_usaCommented:
Have you applied KB931832 and KB950159?

If you are not already using URLScan from Microsoft (ISAPI filter) you should look at installing it.

Here is a paper discussing that type of attack (so you have a better understanding of it and some examples you can use to validate if you are vulnerable - don't blindly trust Qualys or any scanner. Verifiy the results):
http://www.procheckup.com/vulnerability_manager/documents/document_1258758664/bypassing-dot-NET-ValidateRequest.pdf

http://technet.microsoft.com/en-us/security/bulletin/ms07-040
0

Featured Post

Lessons on Wi-Fi & Recommendations on KRACK

Simplicity and security can be a difficult  balance for any business to tackle. Join us on December 6th for a look at your company's biggest security gap. We will also address the most recent attack, "KRACK" and provide recommendations on how to secure your Wi-Fi network today!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now