OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Novell BorderManager 3.0 EE - Encoded URL rule bypass
From: Vitaly Fedrushkov (willyLUKOIL.UU.RU)
Date: Thu Jul 06 2000 - 03:33:07 CDT


Good $daytime,

The same flaw in Squid was discovered (and fixed -- by
Henrik Nordstrom) back in February 1999.

If I recall properly, Apache turned out to be immune to
this problem. I had no other software to check. Now I
see I should have asked others :)

It should be noted that "end result" depends on server
implementation: some servers understand escaped
punctuation such as '/' or '~' but not letters.

Admins reading this -- please check your proxies!
Though if you're using squid >= 1.1.20 -- don't care :)

Thanks for your time.

  Regards,
  Willy.

--
"No easy hope or lies        | Vitaly "Willy the Pooh" 
Fedrushkov
 Shall bring us to our goal, | Control Systems and 
Processes Division
 But iron sacrifice          | LUKoil Company, Chelyabinsk 
branch
 Of Body, Will and Soul."    | mailto:willylukoil.uu.ru  
+7 3512 620367
                   R.Kipling | VVF1-RIPE