Log in

View Full Version : 8e6 Technologies R3000 Internet Filter Bypass with Host Decoy



newsbot
06-08-2008, 09:01 PM
The 8e6 Professional Edition (http://www.8e6.com/network-security/internet-filtering/internet-filtering.html) offers "high-performance, enterprise-level filtering with the R3000 Internet Filter. An appliance optimized for speed and scalability, the R3000 provides 90+ categories and millions of Web sites in the 8e6 Database. Deployed in pass-by or transparent mode, the R3000 sits outside the flow of network traffic to "watch" rather than "stop and check", delivering unmatched network compatibility and performance". A vulnerability in the way 8e6 Technologies R300 filtering HTTP requests can be bypassed by sending it a malformed Host field, this would allow an attacker to bypass the restrictions imposed by the 8e6 solution.

http://www.securiteam.com/securitynews/5ZP021PP5Y.html