Short Name |
HTTP:ISA-AUTH-BYPASS |
---|---|
Severity |
Minor |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft ISA Server 2006 Authentication Bypass |
Release Date |
2009/07/14 |
Update Number |
1461 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to bypass security protections provided by Microsoft Internet Security and Acceleration (ISA) Server 2006, when using Radius One Time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation. Using a crafted request, attackers can bypass authentication allowing for privilege escalation. A successful attack can allow an attacker access to otherwise protected files.
Microsoft ISA Server is prone to an authentication-bypass vulnerability. An attacker with knowledge of a valid account name can exploit this issue to bypass authentication and gain access to arbitrary resources within the context of the selected account.