Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-21 Thread Guy
On Fri, Aug 14, 2009 at 4:17 PM, anto...@santo.franto...@santo.fr wrote: Gone beach for the Week End, more info on monday. Antoine. Lies. -Guy ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

[Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread anto...@santo.fr
Title : ByPass a BlueCoat Proxy 8100 Serie (authentification request AND eventually the 3rd party url filtering solution) Date : 14/08/2009 Author : Antoine Santo ** Test one : Try to browse http://www.fcnantes.com/ Result : I

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread Sebastien gioria
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is it working on all versions ? Le 14 août 09 à 15:10, anto...@santo.fr a écrit : Title : ByPass a BlueCoat Proxy 8100 Serie (authentification request AND eventually the 3rd party url filtering solution) Date : 14/08/2009 Author : Antoine

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread Guy
** Test two : i just add a spoofed http header REFERER to a whitelisted (localdatabase) site Result : W00t !! **

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread anto...@santo.fr
From: Sebastien gioria s...@gioria.org Is it working on all versions ? Tested version : - Software version: SGOS 5.2.4.14 Proxy Edition ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread Guy
** Test two : i just add a spoofed http header REFERER to a whitelisted (localdatabase) site Result   : W00t !! **

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread Alan Buxey
Hi, ** Test two : i just add a spoofed http header REFERER to a whitelisted (localdatabase) site Result : W00t !!

Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread Guy
i think it basically means 'to a site thats been configured as allowed in the configuration of the BC' -   allowed = whitelisted, int he configuration = localdatabase alan Alan, The Bluecoat 8100-C I'm going through has 27 policies in the Web Access Layer. The first policy is configured to