03/18/2010

how malware can bypass a HTTP proxy filter

Many networks have nowadays a proxy filter in place that tries to stop the malware from getting in or out

there seems now to be a few methods that will bypass those protections

First using https instead of http (some botnets do)

You should buy the extension of your proxylicense so you can filter also https traffic

Secondly strangly enough as an xml stream to get out

The website was blocked but it seemed to get transactions out although, through all the security checks. As an XML stream.

This one is still under investigation but once we get the answer we'll publish it

Meanwhile thought to inform you about that one.

16:44 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment