[19751] in bugtraq
SurfControl Bypass Vulnerability
daemon@ATHENA.MIT.EDU (Witter, Franklin)
Wed Mar 21 16:27:29 2001
MIME-Version: 1.0
Content-Type: text/plain
Message-ID: <47795B4647CAD111BE4000805F19303A027634D8@wil-po02-priv>
Date: Tue, 20 Mar 2001 13:06:45 -0500
Reply-To: "Witter, Franklin" <FWitter@BBANDT.COM>
From: "Witter, Franklin" <FWitter@BBANDT.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
It appears that there is yet another way to bypass the site blocking feature
of SurfControl for MS Proxy.
Our configuration:
We have set up our rules to deny access to anyone attempting to reach sites
classified as Adult/Sexually Explicit, Hacking, etc.
That would mean that anyone trying to reach www.blockedsite.com would
normally be denied access to the site.
The workaround:
1. First, do an nslookup on www.blockedsite.com to get the IP address of
the site -- xxx.xxx.xxx.xxx
2. Next, convert each octet to an octal number using the windows calculator
-- yyy.yyy.yyy.yyy
3. Insert eight (8) leading zeros in the first and third octets and seven
(7) leading zeros in the second and fourth octets --
00000000yyy.0000000yyy.00000000yyy.0000000yyy
4. Type the modified octets into your browser's address bar and, viola!,
your are successfully bypassing the SurfControl filter.
I have contacted SurfControl about this but have had no response.
If anyone has any suggestions for correcting this vulnerability, please let
me know.
Franklin Witter
Network Security Specialist II
252-246-3546
fax: 252-246-3463
e-mail: FWitter@BBandT.com