Full Disclosure mailing list archives

Re: ByPass a BlueCoat Proxy 8100 Serie authentification


From: Guy <full-disclosure () nullamatix com>
Date: Fri, 14 Aug 2009 14:34:40 -0400

******************************************************************************************
Test two : i just add a spoofed http header REFERER to a whitelisted (localdatabase) site
Result   : W00t !!
******************************************************************************************

Antoine,

Would you mind sharing the policy (on the bluecoat) you're referring
to for www.mappy.fr? What is the "Action" for that host or IP set to?
You mentioned "whitelisted" but that could mean anything from the list
of options in the policy manager.

Thanks,

Guy

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: