[TOOL] WASap Application Layer Firewall

From: SecuriTeam (support_at_securiteam.com)
Date: 11/05/03

  • Next message: SecuriTeam: "[NT] BRS WebWeaver User-Agent DoS"
    To: list@securiteam.com
    Date: 5 Nov 2003 17:51:07 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      WASap Application Layer Firewall
    ------------------------------------------------------------------------

    DETAILS

     <http://wasap.exis.cl/> WASap is an Apache module (version 1.3.x), which
    acts as an Application level Firewall. It can filter and block malignant
    requests.

    It has the following functionality/features:
     * Purification of modules at server/directory level
     * Individual Configuration for each module
     * chk_class.c: A module which can filter by class by alphanumeric, length
    and metacharacters (more info later ...)
     * etc...

    ADDITIONAL INFORMATION

    The tool can be downloaded from: <http://wasap.exis.cl/>
    http://wasap.exis.cl/.

    The information has been provided by <mailto:pwhelan@exis.cl> Phillip
    Whelan and <mailto:operedo@exis.cl> Oscar Peredo.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] BRS WebWeaver User-Agent DoS"

    Relevant Pages

    • [NEWS] Cisco WSM URL Filtering Solution TCP ACL Bypass Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability exists in the Cisco Firewall Services Module ... The FWSM may be used in conjunction with a Websense Enterprise ... filter is also exempt from the inbound ACL inspection on any interface. ...
      (Securiteam)
    • [NEWS] Hotmail Cross Site Scripting Vulnerability (Malformed Tags)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Hotmail's filter identifies any possibly malicious HTML ... the HTML event properties inside the email s HTML tags. ...
      (Securiteam)
    • [NEWS] Hotmail Cross-Site Scripting Vulnerability (IE gte)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Hotmail's filter identifies any possibly malicious HTML ... In order to bypass this protection, a comment tag can be added before the ... script as an HTML comment. ...
      (Securiteam)
    • [EXPL] phpBB Remote PHP Code Execution (viewtopic.php 2)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The following exploit code utilizes a vulnerability in phpBB to cause ... This bulletin is sent to members of the SecuriTeam mailing list. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [EXPL] TinyWeb Server DoS Exploit
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)