[15783] in bugtraq

home help back first fref pref prev next nref lref last post

Novell BorderManager 3.0 EE - Encoded URL rule bypass

daemon@ATHENA.MIT.EDU (Steve Banks)
Fri Jul 14 14:38:11 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Message-Id:  <TFSFLJPY@shellgasdirect.co.uk>
Date:         Fri, 14 Jul 2000 09:18:28 +0100
Reply-To: steve.banks@SHELLGASDIRECT.CO.UK
From: Steve Banks <steve.banks@SHELLGASDIRECT.CO.UK>
To: BUGTRAQ@SECURITYFOCUS.COM
Content-Transfer-Encoding: 8bit

It doesn't work on by BM3 system - I get a :

Status : 400 Bad Request
Description : Invalid DNS Host IP Address

when I try to connect to http://43243234432/

-Steve
------------------

>>Yes, but has anyoen tried actually doing this with BorderManaer to see if
>>it works? Novell isn't the best at obeying RFC standards, in my opinion.

>>On Mon, 10 Jul 2000, Henrik Nordstrom wrote:

> Knud Erik H=F8jgaard wrote:
>
> > has anyone tried the longip equivalent for the host? (for the few what =
dont
> > know longip, try //echo -a $longip(123.45.67.89) in mIRC ) ... its a ra=
ther
> > old spammer trick.. disguising the urls like http://43243234432/%43%76%=
32


********************
This e-mail may contain confidential information and may also be legally
privileged. If you are not an intended recipient, named above, please notify
us immediately. In any event, you should not copy or use the e-mail for any
purpose, nor disclose its contents to anyone.
********************

home help back first fref pref prev next nref lref last post