Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Symantec Enterprise Firewall HTTP Pattern Matching Evasion Weakness

Symantec Enterprise Firewall allows HTTP requests containing certain patterns to be blocked. When a URL containing a pattern that matches a pattern blocking rule is submitted by a user behind the firewall, that HTTP request will be blocked. If the same URL is encoded using escaped character sequences, Unicode, or UTF-8, the HTTP request will not be blocked.







 

Privacy Statement
Copyright 2008, SecurityFocus