Great Circle Associates Firewalls
(August 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall Java blocking
From: Brian Hatch <bri @ ifokr . org>
Date: Thu, 1 Aug 1996 07:15:53 -0500 (CDT)
To: Steve Betts <Steve_Betts @ ccmailgw . biss . co . uk>
Cc: firewalls @ GreatCircle . COM, James Croall <jcroall @ smiley . mitre . org>
In-reply-to: <9607018389 . AA838914258 @ ccmailgw . biss . co . uk>

 
> I understand how a firewall might be configured to block Java or ActiveX 
> executable files, by looking at the file extension. How does a firewall 
> understand what is JavaScript or VBScript when that code is simply part 
> of a comment in an HTML document? Does it now have to be an HTML 
> interpreter as well?

Each seems to handle this differently, for example some you can
dissable the file extensions (which can be circumvented if you don't
name it .class) whereas others watch the file itself (first few bytes
will give it's type away).  TIS' Gauntlet actually reads the HTML
and can be configured to not pass through anything between an
open tag and it's closing counterpart, thus that section will never
reach the broswer, so they won't request anything from it.

This alone could be circumvented if someone gets the page via other
means than the proxy (brings it from home, ftp's it instead)
I think, but if you can use it in conjunction with extensions/scanning
it seems rather full.

One interesting thing you could do with this however: if you're a 
particularly disorganized person, disable the <ul> and <ol>
tags, or if your corporate policy disallows 'inapropriate' access
of the visual nature, just turn off the <img> tag...   ;-)

						 Bri
--
bri @
 ifokr .
 org
Systems and Security Engineer
Onsight, Inc.  http://www.avue.com/



References:
Indexed By Date Previous: Re: SSL, port 442, https
From: Tony Iannotti <tony @ fozzie . secapl . com>
Next: Re: PPTP thoughts anyone?
From: Bob Resino <pnh1rgr @ mclo10 . med . navy . mil>
Indexed By Thread Previous: Re: Firewall Java blocking
From: "Steve Betts" <Steve_Betts @ ccmailgw . biss . co . uk>
Next: Re: Firewall Java blocking
From: "James Croall" <jcroall @ smiley . mitre . org>

Google
 
Search Internet Search www.greatcircle.com