BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Squid URL Filtering Bypass Apr 19 2012 05:02PM
Mario Vilas (mvilas gmail com)
What I understand from the advisory is the Squid proxy is basing its
filtering on the Host header when present, even for the CONNECT
command which doesn't allow this header at all as it makes no sense. I
haven't confirmed the bug but what's being described is definitely a
vulnerability.

There's als...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus