SquidGuard Bypass Bug (squidGuard Advisory: SG-2007-04-15)
-
The currently available SquidGuard package for pfSense has a bug that allows you to bypass URL filters (domain filters are unaffected).
If you block e.g. the following URLsblog.oregonlive.com/popmusic/
ftd.de/boersen_maerkte/aktien/you'll still be able to access them at
http://blog.oregonlive.com///popmusic/
http://www.ftd.de/boersen_maerkte/%61ktien/This bug affects all SquidGuard versions before 1.2.1 (pfSense uses 1.2.0) - http://www.squidguard.org/Doc/sg-2007-04-15.html .
-
Thanks for report.
-
Were you able to fix this bug yet?