Old 07-15-2011, 01:35 PM   #1 (permalink)
Master Untangler
 
Big D's Avatar
 
Join Date: Nov 2008
Posts: 691
Big D is on a distinguished road
Default Kaseya affected by intrusion prevention rule

Disabling this rule.

#8734: WEB-PHP Pajax arbitrary command execution attempt.

Issue described by other engineers is slow access and timeout issues when accessing Kaseya and navigating the menu options. (machine agent connections to the server don't appear affected)

Believe another post mentioned this rule affecting some webmail portals and web interfaces as well.
__________________
The beatings shall continue until morale improves!
Big D is offline  
Old 07-15-2011, 02:18 PM   #2 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

I've had a programmer buddy of mine (RegEx makes my head hurt) look at the regex that is in that rule.

It seems to me to be a bit over broad. A lot like the SOCK5 rule in the protocol control module.

I think Dirk mentioned in a future release that rule was going to default to pass, to prevent these issues.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:23 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2