Penetration Testing mailing list archives

Re: SMTP over HTTP traffic, looks fishy.


From: zHihaO <zhihao () root sg>
Date: Tue, 04 Jul 2006 16:01:13 +0800

hi killy,

could be due to the fact that smtp traffic coming out from china is filtered heavily at the chinese border routers. even myself tunnel smtp through http ports to get pass all those filtering the chinese government have in place. you might wanna take a look at this : http://en.wikipedia.org/wiki/Internet_censorship_in_China,

./zhihao

killy wrote:
Over the last several days, we have seen a significant increase in the
attempts to tunnel SMTP through HTTP. Most of these attacks have come
out of China in the past.


Can anyone shed a little light into what they are trying to accomplish?



We went from a high average of 400 attempts to 700 in recent days.


TIA

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details. ------------------------------------------------------------------------------





------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: