Firewall Wizards mailing list archives

Re: Air gap technologies


From: Aleph One <aleph1 () underground org>
Date: Wed, 24 Jan 2001 16:09:52 -0800

On Mon, Jan 22, 2001 at 01:36:13PM -0500, Elad Baron wrote:
BTW - if you can do a 100% job of input validation at the CGI itself,
go for it.  But in real life this is usually impossible.

Actually the opposite tends to be true. I assume that the CGI input 
validation component is not vulnerable to URL encoding, UNICODE encoding,
and other IDS web evasion techniques?

P.S. trim your quotes.

Elad Baron
Whale Communications
http://www.whalecommunications.com

-- 
Aleph One / aleph1 () underground org
http://underground.org/
KeyID 1024/948FD6B5 
Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01 
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: