You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ShineWay
"According to this CERT advisory:
'Full-width and half-width encoding is a technique for encoding Unicode
characters. Various HTTP content scanning systems fail to properly scan
full-width/half-width Unicode encoded HTTP traffic. By sending
specially-crafted HTTP traffic to a vulnerable content scanning system,
an attacker may be able to bypass that content scanning system.' A proof of concept affecting IIS is already
being posted to security mailing lists. Cisco IPS and other IDS products are also affected."
The CERT advisory lists 93 systems, with 6 reported as vulnerable
(including 3com, Cisco, and Snort), 5 known not vulnerable (including
Apple and HP), and the rest unknown.