Security Best Practice: Familiarize Yourself with the ASCII Only Response Headers Protection
| Check Point Reference: | SBP-2008-21 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | IPS Research Center | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Web Servers | ||
| Vulnerability Description HTTP Protocol Inspection provides strict enforcement of the HTTP protocol, ensuring these sessions comply with RFC standards and common security practices. Various attacks use binary and other non-ASCII characters to deliver worms and other malicious content to web servers. |
||
|
Vulnerability Details This protection allows you to force all HTTP headers in an HTTP response to be ASCII only. This will prevent some malicious content from passing in the HTTP protocol headers of an HTTP response. |
Protection Overview
This protection detects and blocks header responses which contain non ASCII values.
To configure the defense, select your product from the list below and follow the related protection steps.