[Full-disclosure] noise about full-width encoding bypass?

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Mon May 21 21:06:06 BST 2007


On Mon, 21 May 2007 14:41:58 CDT, Steven Adair said:
> I think you could be on either side, but I would learn towards this being
> a feature than a bug.  Multiple products appear to do the decoding in the
> same manner and intentionally perform this function.

No, they merely *claim* to do it the same way.

>                                                       However, the recent
> advisories that went out were geared towards IDS/IPS products that were
> not designed to be able to recognize such half-/full-width encoded
> traffic.

And if the IDS doesn't do it the *exact* same way, we're just repeating
the mistakes of "using fragmented packets to bypass the IDS", "using X to
bypass the IDS", "using Y to bypass the IDS"... and so on.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070521/39616d17/attachment.bin 


Full-Disclosure is hosted and sponsored by Secunia.