Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Bugtraq: Re: FortiGuard: URL Filtering Application Bypass Vulnerability

Re: FortiGuard: URL Filtering Application Bypass Vulnerability

From: 3APA3A <3APA3A_at_SECURITY.NNOV.RU>
Date: Fri, 4 Jan 2008 22:25:01 +0300

Dear Danux,

--Friday, January 4, 2008, 2:27:58 AM, you wrote to vulnwatch_at_vulnwatch.org:

D> 1.- HTTP Requests are terminated by the CRLF characters.
D> 2.- Forcing to talk via HTTP/1.0 version so that dont send the host header.
D> 3.- Finally, by Fragmenting the GET or POST requests

D> Macula's Analysis: If you dont have properly installed some AV, HIPS,
D> etc, through this vuln, a workstation can connect to a malicious
D> "Hacking Site" and get infected.

 It must be already infected to issue request like this, because all
 standard software always add Host: header and do not fragment request.

D> Also through this vuln, you can
D> connect to different porn sites without problems. And no matter if its
D> or not multi-homed web sites. So we consider its not a low risk.

 O yeah.... It's great security risk. My morality may be affected.

-- 
~/ZARAZA http://securityvulns.com/
Received on Jan 04 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]