Bugtraq mailing list archives

Novell BorderManager 3.0 EE - Encoded URL rule bypass


From: steve.banks () SHELLGASDIRECT CO UK (Steve Banks)
Date: Fri, 14 Jul 2000 09:18:28 +0100


It doesn't work on by BM3 system - I get a :

Status: 400 Bad Request
Description: Invalid DNS Host IP Address

when I try to connect to http://43243234432/

-Steve
------------------

Yes, but has anyoen tried actually doing this with BorderManaer to see if
it works? Novell isn't the best at obeying RFC standards, in my opinion.

On Mon, 10 Jul 2000, Henrik Nordstrom wrote:

Knud Erik H=F8jgaard wrote:

has anyone tried the longip equivalent for the host? (for the few what =
dont
know longip, try //echo -a $longip(123.45.67.89) in mIRC ) ... its a ra=
ther
old spammer trick.. disguising the urls like http://43243234432/%43%76%=
32

********************
This e-mail may contain confidential information and may also be legally
privileged. If you are not an intended recipient, named above, please notify
us immediately. In any event, you should not copy or use the e-mail for any
purpose, nor disclose its contents to anyone.
********************


Current thread: