|
COMMAND Norton Anti-Virus content filtering bypasses using capitalized letters SYSTEMS AFFECTED NAV ?? PROBLEM In 3APA3A white paper on content filtering weakness in common software [http://www.security.nnov.ru/advisories/content.asp] : Most MUAs ignore case of Content-Type and Content-Disposition headres while content filtering software may behave in different way. It makes it possible to bypass content-filtering software by using header like CONTENT-type: text/plain; NAme=\\\"eicar.com\\\" SOLUTION Patch ??