SurfControl Filter Bypass Vulnerability
BID:2910
Info
SurfControl Filter Bypass Vulnerability
| Bugtraq ID: | 2910 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 18 2001 12:00AM |
| Updated: | Jun 18 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on June 18th, 2001 by <[email protected]>. |
| Vulnerable: |
SurfControl SuperScout 3.0.2 SurfControl SuperScout 3.0.1 SurfControl SuperScout 2.6.1 .6 SurfControl CyberPatrol 5.0 |
| Not Vulnerable: | |
Discussion
SurfControl Filter Bypass Vulnerability
SurfControl is a series of products designed to filter out harmful or questionable Internet content.
The filtering mechanism for SurfControl Products is rendered ineffective if the attacker uses a proxy server to access restricted content. This is due to the fact that proxy servers split requests into multiple packets that SurfControl products do not handle properly and therefore cannot filter.
Attackers can exploit this vulnerability to view unsafe or prohibited content.
SurfControl is a series of products designed to filter out harmful or questionable Internet content.
The filtering mechanism for SurfControl Products is rendered ineffective if the attacker uses a proxy server to access restricted content. This is due to the fact that proxy servers split requests into multiple packets that SurfControl products do not handle properly and therefore cannot filter.
Attackers can exploit this vulnerability to view unsafe or prohibited content.
Solution / Fix
SurfControl Filter Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.