|
|
| |
| The 8e6 Professional Edition offers "high-performance, enterprise-level filtering with the R3000 Internet Filter. An appliance optimized for speed and scalability, the R3000 provides 90+ categories and millions of Web sites in the 8e6 Database. Deployed in pass-by or transparent mode, the R3000 sits outside the flow of network traffic to "watch" rather than "stop and check", delivering unmatched network compatibility and performance". A vulnerability in the way 8e6 Technologies R300 filtering HTTP requests can be bypassed by sending it a malformed Host field, this would allow an attacker to bypass the restrictions imposed by the 8e6 solution. |
| |
Credit:
The information has been provided by nnposter.
|
| |
Vulnerable Systems:
* 8e6 Technologies R3000 version 2.0.12.10
The HTTP URL filtering function provided by the 8e6 Technologies R3000 Internet Filter contains a vulnerability in that it can mistake a properly formed custom header for the Host header. This can be exploited for bypassing the filter by providing an allowed site in the custom header.
Examples:
GET / HTTP/1.0
X-DecoyHost: www.allowed.org
Host: www.blocked.org
GET / HTTP/1.0
X-Decoy: Host: www.allowed.org
Host: www.blocked.org
This weakness cannot be leveraged for circumventing blocks based on IP addresses (as opposed to DNS names).
The vulnerability has been identified in version 2.0.12.10. However, other versions may be also affected.
|
| Subject:
|
help |
Date: |
22 Sep. 2008 |
| From: |
hollisterboy1221 |
| can anyone explain this in easy terms |
|
| Subject:
|
Huh |
Date: |
28 Oct. 2008 |
| From: |
CowzRule101 |
| If you have to place "e;X-Decoy: Host: www.allowed.org"e; on the adress bar or any of those examples, then it is blocked on my computer...
|
|
| Subject:
|
terms for non hacker step by step please |
Date: |
3 Nov. 2009 |
| From: |
Schoolhackz3136 |
i need a step by step walk through on how to get past my 8e6 R3000 ,im on a macbook with windows installed to it(my school is dumb) it blocks just about anything and i need to get past it in order to look at something in school.
please reply to this within 30 minuets/if not contact me at hren3136@yahoo.com.
ASAP
please and thank you |
|
| Subject:
|
SSH |
Date: |
19 Nov. 2009 |
| From: |
Team Blessdstrygmail.com |
| Iv spent a lot of time trying to find a way around.... I got one get your self a SSH Server and Putty and your golden. By tunneling everything into ssh u can get around anything. |
|
|
|
|