SYSTEM WARNING: 'date_default_timezone_get(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone.' in '/usr/share/mantis/www/core.php' line 264

0000196: HTTPS bypasses content filter domain block list - MantisBT Endian Bugtracker
Endian Issue Tracker





Please see now our new Bugtracker system: JIRA








View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0000196Endian FirewallApplication Level Proxiespublic2007-06-23 13:262008-02-02 07:28
Reporterhooptie 
Assigned Topeter-endian 
PrioritynormalSeverityminorReproducibilityalways
StatusclosedResolutionfixed 
PlatformOSOS Version
Product Version2.1 
Target VersionFixed in Version2.2-beta1 
Summary0000196: HTTPS bypasses content filter domain block list
DescriptionI'm trying to block access to web proxies setup by peacefire.org. Unfortunately, users can use https:// to bypass the content filter entirely. If a domain name / ip address is in the blocklist and is transmitted over the network in cleartext, why is it still bypassing the content filter?

The only solution I've found is to disallow port 443 on the "Allow SSL Ports" under the proxy configuration; however, that has a number other more-annoying side effects. Any idea why?
TagsNo tags attached.
Attached Files

- Relationships

-  Notes
(0000579)
peter-endian (administrator)
2007-10-27 21:15

Should not be anymore a problem within version 2.2
Could you please try and report back?

- Issue History
Date Modified Username Field Change
2007-06-23 13:26 hooptie New Issue
2007-10-27 21:15 peter-endian Status new => resolved
2007-10-27 21:15 peter-endian Fixed in Version => 2.2
2007-10-27 21:15 peter-endian Resolution open => fixed
2007-10-27 21:15 peter-endian Assigned To => peter-endian
2007-10-27 21:15 peter-endian Note Added: 0000579
2007-12-20 20:48 Anonymous Note Added: 0000709
2007-12-20 20:48 Anonymous Status resolved => confirmed
2008-01-08 12:15 peter-endian Note Deleted: 0000709
2008-01-08 12:16 peter-endian Status confirmed => resolved
2008-02-02 07:28 raphael-endian Status resolved => closed

Copyright © 2005-2008 Endian, SRL. All rights reserved.


Copyright © 2000 - 2012 MantisBT Group
Powered by Mantis Bugtracker