Re: RPC over HTTPs through ISA 2006, still a security hole?



With ISA 2006 I use the SSL certificate (including private key VERY IMPORTANT) in "SSL Listener" that is the same as on my exchange server 2003. According to what I have read, this should provide for decryption and inspection of traffic.


--
Edward Ray
CCIE Security, CISSP, GCIA Gold, GCIH Gold, MCSE+Security, PE

"Henrik Zawischa" <hzawischa@xxxxxxxxxxxxx> wrote in message news:OsRTs2qGHHA.4580@xxxxxxxxxxxxxxxxxxxxxxx
Henrik Zawischa wrote:
Big Daddy Jay wrote:
Is the following still true (or better yet can I get confirmation this is/was
the case with ISA 2004 even) with ISA 2006??


RPC-Over-HTTP Traffic Not Inspected

Problem: RPC over HTTP traffic encrypts the RPC data in HTTP. RPC over HTTP
data is not inspected by ISA Server 2004.

Cause: In regular Web publishing scenarios, ISA Server can inspect the HTTP
headers and body. However, the RPC filter designed to inspect RPC traffic
cannot inspect RPC over HTTP requests, and does not protect against RPC
exploits reaching the Exchange server. In outbound scenarios, RPC over HTTP
requests over SSL are tunneled, and no inspection takes place of the HTTP
headers or body following the initial connection.




At least it is not logged. The HTTP-filter works, you can limit the
methods, extensions, URL and query length. All these work.

Henrik
Forgot the main part: as far as I can see, RPC filters are still not
applied.

.



Relevant Pages

  • Re: Exchange, Outlook and DNS problem
    ... > Company deceided to switch from ISP POP3 to local Exchange server. ... > Cisco routes to local ISA IP address.ISA is configured to do RPC over ... > HTTP routing for Exchange which is also located in internal network. ... > Outlook while connected internal network. ...
    (microsoft.public.win2000.dns)
  • RE: RPCPING error 12007
    ... Mailbox definately exists. ... Confirmed that RPC Proxy is using default ports, ... I can NOT access OWA via HTTPS but I can via HTTP. ... > You are unable to use RPC over HTTP to connect to the Exchange Server. ...
    (microsoft.public.exchange.connectivity)
  • RE: RPC over HTTP troubleshooting
    ... When we connect to the server through RPC over HTTPS, ... HTTP Error 401.3 - Unauthorized: Access is denied due to an ACL set on the ... 833401 How to configure RPC over HTTP on a single server in Exchange Server ...
    (microsoft.public.exchange.connectivity)
  • RE: Is it possible to send fax from Outlook over http/rpc ?
    ... can send fax via RPC over HTTP. ... Based on my knowledge, in a local area network, Outlook communicates ... RPC over TCP/IP. ... Exchange Server accounts from the Internet when they are working outside ...
    (microsoft.public.windows.server.sbs)
  • Re: RPC Over HTTP Security
    ... 833401 How to configure RPC over HTTP in Exchange Server 2003 ... >> select the "encrypt" option on the security page in the Outlook email ...
    (microsoft.public.exchange2000.general)