Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Novell BorderManager 3.0 EE - Encoded URL rule bypass

Re: Novell BorderManager 3.0 EE - Encoded URL rule bypass

From: Knud Erik Højgaard <kain_at_EGOTRIP.DK>
Date: Thu, 6 Jul 2000 13:09:41 +0200

has anyone tried the longip equivalent for the host? (for the few what dont
know longip, try //echo -a $longip(123.45.67.89) in mIRC ) ... its a rather
old spammer trick.. disguising the urls like http://43243234432/%43%76%32

Sincerely

Knud Erik Højgaard <knud_at_cybercity.dk>
Cybercity Support <support_at_cybercity.dk>

http://www.cybercity.dk/support/

----- Original Message -----
From: Kevin R Smith <Kevin.Smith_at_FIRSTDATACORP.CO.UK>
To: <BUGTRAQ_at_SECURITYFOCUS.COM>
Sent: Wednesday, July 05, 2000 1:23 PM
Subject: Novell BorderManager 3.0 EE - Encoded URL rule bypass

> I suspect that this has already been defined, but I cannot find any
reference to it.
>
> Setting secure areas on an intranet secured by URL rules within
bordermanager can be bypassed by changing some of the characters in the URL
with %-encoded triplets. To access http://home.myintranet.com/secure use
http://home.myintranet.com/s%45cure
>
> It doesn't work for characters in the main domain name, nut sub-folders
seem to work ok.
>
> I haven't seen any mention of this in any TIDs or service packs for BM, so
I assume the fault carries over into version 3.5?
>
>
> Regards,
> Kevin R Smith
Received on Jul 06 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos