<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199852#M33383</link>
    <description>&lt;P&gt;Perhaps not a direct solution but are you already leveraging the configurations outlined in&amp;nbsp;&lt;SPAN&gt;sk180808, sk105740 to restrict access to portal URLs?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 10:42:52 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-12-06T10:42:52Z</dc:date>
    <item>
      <title>Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/195396#M32765</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I'm working with an Check Point customer in the Financial Sector to resolve their external ASV scan findings.&lt;/P&gt;
&lt;P&gt;We've managed to resolve all findings but one - "Redirection via Arbitrary Host Header Manipulation".&amp;nbsp; The ASV vendor cannot really provide any information apart from a link to &lt;A href="https://cwe.mitre.org/data/definitions/20.html" target="_self"&gt;mitre.org&amp;nbsp;&lt;/A&gt;that gives some vague guidance about input validation.&amp;nbsp; Even google just comes up with a handful of links.&lt;/P&gt;
&lt;P&gt;The gateways in question are running R80.40 T198 and handles C2S VPN access with Office mode.&lt;/P&gt;
&lt;P&gt;Any and all input and guidance appreciated:-)&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 17:14:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/195396#M32765</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-10-17T17:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/195433#M32768</link>
      <description>&lt;P&gt;Without more details about the issue, it's difficult to comment.&lt;BR /&gt;Is there a CVE number for the issue?&lt;/P&gt;
&lt;P&gt;You may also want to try enabling the HTTP Host Header Injection protection in IPS as well.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://advisories.checkpoint.com/defense/advisories/public/2020/cpai-2020-0286.html/" target="_blank"&gt;https://advisories.checkpoint.com/defense/advisories/public/2020/cpai-2020-0286.html/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:42:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/195433#M32768</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-17T14:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/195450#M32769</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;
&lt;P&gt;Unfortunately the best this ASV vendor could is the link I shared - not very helpful.&amp;nbsp; I'm also wondering if it might not be a false positive - they're hitting port 80 and the gateway redirects to 443 - their crappy scanning software then interprets this as successful Host Header Manipulation.&lt;/P&gt;
&lt;P&gt;Thanks for the lead on the IPS signature, will enable and see if it makes a difference.&lt;/P&gt;
&lt;P&gt;P.S. Must also commend TAC for their willingness to assist - they've requested that I do a packet capture at the time of the scan so that they can see what's happening.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 16:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/195450#M32769</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-10-17T16:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199851#M33382</link>
      <description>&lt;P&gt;Hi Ruan,&lt;/P&gt;&lt;P&gt;I have the same issue on R81.10 with JHF T110.&lt;/P&gt;&lt;P&gt;The ASV vendor told us, that by Hostheader manipulation it will be possible to be redirected to a different Site.&lt;/P&gt;&lt;P&gt;You can check this by:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; curl -VL &lt;A href="http://&amp;lt;Cluster" target="_blank"&gt;http://&amp;lt;Cluster&amp;nbsp;&lt;/A&gt;IP&amp;gt;/ -H "Host: example.com".&lt;/P&gt;&lt;P&gt;They told us to deactivate the Redirect. But this seems to be impossible. (implied Rules)&lt;/P&gt;&lt;P&gt;Or to check the Hostheader against a Whitelist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Didn`t find out how to solve this issue.&amp;nbsp; Both solutions can not be configured&amp;nbsp; on the Firewall.&lt;/P&gt;&lt;P&gt;If anyone can provide a solution, I would be very grateful!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 09:46:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199851#M33382</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2023-12-06T09:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199852#M33383</link>
      <description>&lt;P&gt;Perhaps not a direct solution but are you already leveraging the configurations outlined in&amp;nbsp;&lt;SPAN&gt;sk180808, sk105740 to restrict access to portal URLs?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 10:42:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199852#M33383</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-06T10:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PCI ASV Scan - Redirection via Arbitrary Host Header Manipulation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199868#M33386</link>
      <description>&lt;P&gt;You probably need to do something like:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk165937" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk165937&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 14:24:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-PCI-ASV-Scan-Redirection-via-Arbitrary-Host-Header/m-p/199868#M33386</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-06T14:24:45Z</dc:date>
    </item>
  </channel>
</rss>

