Bypass surfControl URL Blocking
Reported Feburary 4, 2000 by Mike C
- surfControl Scout 220.127.116.11
surfControl Scout is a package designed to block access to specified URLs. However, by appending a period to the end of a URL a blocked URL may still be accessed, thereby bypassing the rules defined in the surfScout application.
DEMONSTRATION If the URL http://www.some-blocked-site.com were blocked by surfScout rules then the site could be accessed be entering http://www.some-blocked-site.com. --- notice the period on the end of the URL.
<font face="Verdana" size="2" color="#b50016"><strong>VENDOR RESPONSE</strong></font> The vendor has released a patch that upgrades 2.1.6.x versions to 18.104.22.168, as well as a complete version 22.214.171.124 package for download.
Discovered by Mike C