scip_Advisory 3808 - D-Link DIR-100 long url filter evasion
http://www.scip.ch/?vuldb.3808
D-Link DIR-100 is a small and cost-effective router and firewall device for small offices and home users.
Marc Ruef at scip AG found a possibility to evade url filters of the web proxy to prevent access to web sites. An attacker might add a very long string to the url to access web resources althought their access is forbidden. It is possible to exploit the vulnerability with a common web browser by using a long url (approx. 1'300 chars). You can expand the length of the url by adding a non-used http get request parameter.
Detection of web based attacks requires a specialized web proxy and/or intrusion detection system. Patterns for such a detection are available and easy to implement.
We have informed D-Link on an early stage. Our technical requests were not answered nor confirmed. Therefore, not official statement, patch or upgrade is available. We suggest the use of another device for filtering forbidden web resources successfully.
Other Videos By Marc Ruef
2012-06-03 | Cybersecurity und Cybercrime (Welt der Wunder, RTL2) |
2012-05-14 | Automated Firewall Rule Analysis Proof-of-Concept |
2011-10-30 | The IT Crowd s02e04 - The Dinner Party (2007) |
2011-09-18 | Tennis US Open 2011: Nadal vs. Djokovic - Little Britain Reference |
2010-02-20 | Application Mapping Example with AMAP |
2010-02-20 | HTML Injection Example |
2010-02-20 | Webserver Error Site Fingerprinting |
2009-09-25 | iPhone Backdoor GPS Tracking |
2009-08-05 | Burnout Paradise (PS3) - Platinum Trophy Success |
2009-06-05 | Xdoor Demo - Ajax-based Backdoor / Trojan Horse |
2008-09-08 | scip_Advisory 3808 - D-Link DIR-100 long url filter evasion |
2008-06-08 | Field - E-Beggar (Demo Schmitz Remix) |
2007-06-18 | The Bass Man in Anger Management |
2006-12-12 | Computec TV 2: Topologische Überlegungen zu Firewalls |
2006-12-10 | Computec TV 3: Telefon-Spionage für Anfänger |
2006-12-10 | Computec TV Pilotsendung: Klassisches ICMP-Mapping |