|
Brought to you by:
Suppliers of:
|
|
|
| |
| Zone Lab's IMsecure allows a user to further protect his computer from malicious content by actively filtering potentially dangerous URLs containing files with extensions such as vbs, scr and exe. A vulnerability in the Zone Lab's IMsecure allows an attacker to bypass this protection by encoding part of the extension. |
| |
Credit:
The information has been provided by Paul Kurczaba.
The original article can be found at: http://www.kurczaba.com/html/security/0410141.htm
|
| |
Vulnerable Systems:
* ZoneLabs IMsecure and IMsecure Pro version 1.4 and prior
Immune Systems:
* ZoneLabs IMsecure and IMsecure Pro version 1.5
The active link filter is programmed to block any potentially dangerous URLs in IM messages. For example, IMsecure will remove URLs with extensions of .vbs, and .exe. By encoding characters in the file extension of the URL, it is possible to bypass the Zone Lab's active link filtering mechanism.
Proof of Concept:
While IMsecure's protection mechanism is enabled accessing: http://www.example.com/somefile.e%78e would allow to download an otherwise blocked executable file. In the example, "78" is the encoded form of "x".
|
|
|
|
|