Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate V5.6

From: ivan.buetlerat_private
Date: Mon Jan 27 2003 - 14:16:05 PST

  • Next message: Nick Jacobsen: "z/OS, OS/390 Pen testing tips/ideas/papers?"

    #############################################################
    #
    # COMPASS SECURITY                        http://www.csnc.ch/
    # 
    #############################################################
    #
    # Topic:        Tech-Article
    # Betreff:      HTTP/S Content Filter Analysis - Finjan SurfinGate V5.6
    # Autor:        Jan Monsch & Ivan Buetler
    # Date:         27. January 2003
    # 
    #############################################################
    
    Dear Reader
    
    As you might know - malicious mobile code contamination via web download 
    becomes a real threat. HTTP content filter techniqe promises protection at 
    your perimeter infrastructure. While penetrating the clients' infrastructure 
    during a pen-test job, we are ready to use bypass technique in order to 
    successfully exploiting the clients security mechanism. This article is 
    focussed in Finjan SurfinGate HTTP content filter protection - and gives you 
    a better understanding of threats and risks. 
    
    We have used Finjan SurfinGate V5.6. The new V6.0 is already available. 
    
    Find the analysis:
    
    http://www.csnc.ch/downloads/docs/techdocs/FinjanSurfinGate_Analysis_CSNC_V3.0.pdf
    
    Kind Regards
    
    Compass Security TEAM
    
    
    
    
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Tue Jan 28 2003 - 12:00:31 PST