<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS module bypass in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505792#M237489</link>
    <description>&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;&lt;DIV class="field-items"&gt;&lt;DIV class="field-item even" property="content:encoded"&gt;&lt;P&gt;hi experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are using cisco ips module in cico asa firewall 5520&lt;/P&gt;&lt;P&gt;the ips is working fine and it stops sql injections as seen from log&lt;/P&gt;&lt;P&gt;however, one coleague&amp;nbsp;showed me how he can bypass the ips using one software that sends the username ‘ or 1=1 –&amp;nbsp;encoded (url encoder/decoder)&lt;/P&gt;&lt;P&gt;is there any way to let the ips checks the username as clear text and also&amp;nbsp;as encoded ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:20:26 GMT</pubDate>
    <dc:creator>ohassairi</dc:creator>
    <dc:date>2019-03-12T04:20:26Z</dc:date>
    <item>
      <title>IPS module bypass</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505792#M237489</link>
      <description>&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;&lt;DIV class="field-items"&gt;&lt;DIV class="field-item even" property="content:encoded"&gt;&lt;P&gt;hi experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are using cisco ips module in cico asa firewall 5520&lt;/P&gt;&lt;P&gt;the ips is working fine and it stops sql injections as seen from log&lt;/P&gt;&lt;P&gt;however, one coleague&amp;nbsp;showed me how he can bypass the ips using one software that sends the username ‘ or 1=1 –&amp;nbsp;encoded (url encoder/decoder)&lt;/P&gt;&lt;P&gt;is there any way to let the ips checks the username as clear text and also&amp;nbsp;as encoded ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505792#M237489</guid>
      <dc:creator>ohassairi</dc:creator>
      <dc:date>2019-03-12T04:20:26Z</dc:date>
    </item>
    <item>
      <title>To my knowledge this is not</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505793#M237491</link>
      <description>&lt;P&gt;To my knowledge this is not possible using IPS.&amp;nbsp; IPS filters based on signatures from Cisco, manually configured signatures, traffic anomoly...etc.&amp;nbsp; So the IPS does not check and authenticate users, devices, and does not do MAB which is authentication.&amp;nbsp; For this you would need to have an ISE or similar user access control device.&lt;/P&gt;&lt;P&gt;You may also need to add exceptions to the IPS to allow the sql traffic as well...but then you may or may not want to also have user authentication in addition.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505793#M237491</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-18T08:14:18Z</dc:date>
    </item>
    <item>
      <title>Hello, To fix that issue you</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505794#M237496</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To fix that issue you should check your &lt;SPAN class="GINGER_SOFTWARE_mark" ginger_software_uiphraseguid="5c43057b-a2b1-4d20-afd7-bc24d01a4ab4" id="d5e644be-181a-4931-a52b-e1a31e63fb0d"&gt;sql&lt;/SPAN&gt; configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 12:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-bypass/m-p/2505794#M237496</guid>
      <dc:creator>Juraj Papic</dc:creator>
      <dc:date>2014-06-18T12:41:14Z</dc:date>
    </item>
  </channel>
</rss>

