CERT-In Vulnerability Note
CIVN-2004-0063
Microsoft ISA Server / Proxy Server Internet Content Spoofing Vulnerability
Original Issue Date:November 10, 2004
Severity Rating: MEDIUM
Systems Affected
- Internet Security and Acceleration Server 2000 Service Pack 1 SP1 , SP2
- Microsoft Small Business Server 2000
- Microsoft Small Business Server 2003 Premium Edition
- Microsoft Proxy Server 2.0 SP1
Overview
A vulnerability exists in the method used by the Proxy Server 2.0 and ISA Server 2000 to cache reverse lookup results which can be exploited by an attacker to spoof Internet content.
Impact
An attacker could exploit this vulnerability to spoof trusted Internet content and victims may be tricked to access malicious Internet content instead of trusted Internet content. However, an attacker would have to entice a user to visit the attacker's site in order to exploit this vulnerability.
Description
Domain Name Server translates domain names into IP addresses. DNS also supports reverse lookup process which enables clients to use a known IP address during a name query and lookup a computer name based on its address. The abovementioned affected systems cache the results of a reverse lookup and use that result for a forward normal lookup.
This DNS cache can be poisoned by providing a spoofed reverse lookup response for a particular domain name. If a user tries to access a resource, record of which has been "poisoned" by the attacker, the request would be routed to the incorrect IP address, which may be hosting a malicious website.
Workaround
Setting the DNS Cache size to zero effectively disables DNS caching on the affected system. However this may affect the DNS resolution. For detailed procedures refer: http://support.microsoft.com/kb/ 889189
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS04-039
Note: This vulnerability doesnt affect the Windows XP Service Pack 2 . Users may consider applying Windows XP Service Pack 2.
Vendor Information
Microsoft Corporation
http://www.microsoft.com/technet/security/bulletin/MS04-039 .mspx
References
Microsoft Security Bulletin MS04-039
http://www.microsoft.com/technet/security/bulletin/MS04-039.mspx
http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/sag_DNS_und_ReverseLookup.htm
Secunia Advisory SA12959
http://secunia.com/advisories/13147/
CVE Name
CAN-2004-0892
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|