Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: New Snort Bypass - Patch - Bypass of Patch Jun 02 2006 11:16PM
M. Dodge Mumford (dodge nfr net)
Sigint Consulting said:
> However we can once again bypass this by including our CR character
> before our string like so:
>
> perl -e 'print "GET \x0d/index.php\x90\x90 HTTP/1.0\n\r\n"'|nc
> 192.168.1.3 80
>
> No alert is generated from the string above.

[...]

> We are not sure how much this ma...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus