How can you send 'malware' over port 443 to mywebserver ?

How can you send 'malware' over port 443 to mywebserver ?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How can you send 'malware' over port 443 to mywebserver ? Marlon Brown 06-19-2005
Posted by Marlon Brown on June 19, 2005, 7:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Often I hear people saying that one of the benefits of an application layer
firewall (let's say ISA 2004) is that SSL traffic can be unencrypted,
scanned and then re-encrypted and sent to the respective webserver.

My question is this:
What's the mechanism that could allow somebody to send, let's say a virus or
a malware over port 443 that could hurt my OWA server, for example ? Since
people is retrieving data from such web server (that is now protected by
ISA), I don't understand well the process that you could use to submit data
over this SSL tunnel and hit the webserver that way.




Posted by Roger Abell [MVP] on June 20, 2005, 1:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Let say the webserver has more than just static html that it serves.
That means it "runs code", some server-side processing that responds to
the page hits and renders the downstream response. Now, in responding
it probably is sensitive to what was posted, rather than just sending the
same response back to all htis all of the time. So, whether that is some
code-behind in Asp.Net, or some php or pl handler, or an older isapi dll,
if it has known error conditions that the hit content can trigger and also
usefully exploit, then one can (sometimes) get a foot in the door

--
Roger Abell
Microsoft MVP (Windows Server: Security)

> Often I hear people saying that one of the benefits of an application
> layer firewall (let's say ISA 2004) is that SSL traffic can be
> unencrypted, scanned and then re-encrypted and sent to the respective
> webserver.
>
> My question is this:
> What's the mechanism that could allow somebody to send, let's say a virus
> or a malware over port 443 that could hurt my OWA server, for example ?
> Since people is retrieving data from such web server (that is now
> protected by ISA), I don't understand well the process that you could use
> to submit data over this SSL tunnel and hit the webserver that way.
>
>
>



Similar ThreadsPosted
Port scan says port 21 is open June 21, 2007, 12:51 pm
IE Send Mail September 20, 2005, 4:42 pm
Where to send fraud e-mails? September 21, 2005, 10:32 pm
Re: AIM Send out random messages May 26, 2005, 5:05 pm
Re: AIM Send out random messages May 26, 2005, 6:12 pm
Does Norton AV send emails ? December 14, 2006, 12:05 pm
Send email thru excel December 29, 2006, 10:16 am
Getting bounced emails that I did not send. May 17, 2008, 1:05 am
I am looking for the classic "Send Keys" program May 14, 2008, 2:55 pm
Send current user token to IIS server August 25, 2006, 7:37 am

The site map in XML format XML site map

Contact Us | Privacy Policy