Bugtraq mailing list archives

Novell BorderManager 3.0 EE - Encoded URL rule bypass


From: Kevin.Smith () FIRSTDATACORP CO UK (Kevin R Smith)
Date: Wed, 5 Jul 2000 12:23:12 +0100


I suspect that this has already been defined, but I cannot find any reference to it.

Setting secure areas on an intranet secured by URL rules within bordermanager can be bypassed by changing some of the 
characters in the URL with %-encoded triplets.  To access http://home.myintranet.com/secure use 
http://home.myintranet.com/s%45cure 

It doesn't work for characters in the main domain name, nut sub-folders seem to work ok.

I haven't seen any mention of this in any TIDs or service packs for BM, so I assume the fault carries over into version 
3.5?

Regards,
Kevin R Smith


Current thread: