Various Vulnerabilities in ZoneAlarm MailSafe

2002-04-02 Thread Edvice Security Services
Tuesday April 2, 2002 Various Vulnerabilities in ZoneAlarm MailSafe * Scope --- Edvice recently tested ZoneLabs ZoneAlarm Pro ability to detect and quarantine incoming e-mail attachments that may contain malicious code or viruses. This

Various problems in Ternd Micro AppletTrap Script filtering

2001-07-29 Thread eDvice Security Services
Sunday 29 July 2001 Various problems in Ternd Micro AppletTrap Script filtering === This is a different advisory than the one we posted on July 9 (http://archives.neohapsis.com/archives/bugtraq/2001-07/0129.html). Product Background --

Various problems in Ternd Micro AppletTrap URL filtering

2001-07-09 Thread eDvice Security Services
Monday 9 July 2001 eDvice Security Services Advisory - Various problems in Trend Micro AppletTrap URL filtering Product Background -- Trend Micro AppletTrap is a product for blocking malicious Java applets, malicious JavaScript and unsecured ActiveX controls at the gateway. The

Aladdin eSafe Gateway Script-filtering Bypass through Unicode Vulnerability

2001-05-29 Thread eDvice Security Services
29 May 2001 This is the third of 3 sequential advisories we are issuing regarding Aladdin eSafe Gateway. Status The entire content of this advisory was reviewed and acknowledged by Aladdin. Product Background -- eSafe Gateway is an Internet Content Security prod

Aladdin eSafe Gateway Script-filtering Bypass through HTML tags

2001-05-29 Thread eDvice Security Services
ing scripts to penetrate their systems. These hostile sites can easily bypass eSafe by adding the code to an href tag or any other tag. Even worse is the false sense of security given by Aladdin's claim that all scripts are removed from the HTML files. ==== Discovered b

Aladdin eSafe Gateway Filter Bypass - Updated Advisory

2001-05-29 Thread eDvice Security Services
able to this attack, see our following two advisories for vulnerabilities in version 3.0. Discovered by: eDvice Security Services [EMAIL PROTECTED] http://www.edvicetech.com Tel: +972-3-6120133 Fax: +972-3-6954837

Vulnerability discovered in SpearHead NetGap

2001-05-28 Thread eDvice Security Services
ng until vendor releases a fix. ======== Discovered by: eDvice Security Services [EMAIL PROTECTED] http://www.edvicetech.com Tel: +972-3-6120133 Fax: +972-3-6954837

Aladdin eSafe Gateway script filter bypass

2001-05-20 Thread eDvice Security Services
n the inner " " will be extracted and we will be left with the following HTML code: alert("hi"); Solution -- Do not rely on eSafe Gateway for HTML filtering until Aladdin fixes the problem. Discovered by: eDvice Security Services [EMAI