Re: Most Popular Hardware Firewalls?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Most Popular Hardware Firewalls?

From: Sebastian Gottschalk <seppi@seppig.de>
Date: Mon Feb 27 2006 - 04:26:54 CET

Leythos wrote:

> Yep, I have three teens and a couple thousands seats for clients - I've
> seen about everything on the market and some home grown attempts to get
> past the firewall. In 20+ years we've never had a compromised network.

It's not about compromising the network but about simply circumventing
the censorship. Believe me, they do, and you won't notice.

> You don't know much about firewalls, do you? I can block downloads,
> content types, cookies, and ActiveX in my WatchGuard units - which makes
> most of the threats to IE meaningless. Oh, and I can do it based on the
> User or the IP of the workstation.

<script>eval(unescape($escaped_evil_script))</script>

Or what about

<style type="text/css">
.??????????????????????(x86 binary code here) p:first-letter {
border-bottom: 1px solid; }
</style>
<div class="??????????????????????(x86 binary code
here)"><p><strong>a</strong></p></div>

? Gonna filter all CSS? What about links containing "sysimage:"? Or "ftp:"?
Received on Mon May 1 00:53:17 2006