On Wed, May 30, 2001 at 11:27:25PM +1200, David McNab wrote:
> Hate to say this, but the FWproxy withing Freeweb is immune to this problem
> :)
Really? It handles unicode scripts, or does it just block all HTTP access from
freenet pages? The latter could still lead to anonymity loss if javascript can
insert into freenet via POST on the portal page.
> 
>     ----- Original Message -----
>     From: toad
>     To: devl at freenetproject.org
>     Sent: Wednesday, May 30, 2001 23:21
>     Subject: [freenet-devl] Content filter vs unicode
> 
>     The attached file (recently posted to bugtraq by "eDvice Security 
> Services"
>     <support at edvicetech.com> as an exploit to another filter proxy) is 
> picked
>     up by
>     fproxy's filter, but only the meta tag that sets the character set. This 
> is
>     used
>     by, for example, the Freenet China News sites, though they use charset=
>     gb2312
>     (and have hyperlinks; they are picked up on the content filter on both
>     counts).
>     Point is, any foreign language web page, even without hyperlinks, will 
> trip
>     the
>     filter. Therefore foreign language freesite readers will turn off the
>     content
>     filter. Isn't there some java support for this stuff? (finding which chars
>     could
>     correspond to an "<script" ?).
>     --
>     Always hardwire the explosives
>             -- Fiona Dexter quoting Monkey, J. Gregory Keyes, Dark Genesis
> 

-- 
Always hardwire the explosives
        -- Fiona Dexter quoting Monkey, J. Gregory Keyes, Dark Genesis

_______________________________________________
Devl mailing list
Devl at freenetproject.org
http://lists.freenetproject.org/mailman/listinfo/devl

Reply via email to