[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification



> ******************************************************************************************
> Test two : i just add a spoofed http header REFERER to a whitelisted 
> (localdatabase) site
> Result   : W00t !!
> ******************************************************************************************

Antoine,

Would you mind sharing the policy (on the bluecoat) you're referring
to for www.mappy.fr? What is the "Action" for that host or IP set to?
You mentioned "whitelisted" but that could mean anything from the list
of options in the policy manager.

Thanks,

Guy

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/