Feeds

Aladdin eSafe Gateway ‘unsafe’

Silly and trivial error

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

A flaw with a content security product means it could be easily compromised by a maliciously constructed Web page.

By using specially crafted HTML files, an attacker can easily bypass the script-filtering mechanism of eSafe Gateway, which is marketed by Aladdin Knowledge Systems.

The flaw was discovered by security firm eDvice Security Services which said users should "not rely on eSafe Gateway for HTML filtering until Aladdin fixes the problem".

Details of the problem, which is believed to affect version 3 eSafe Gateway, and possibly earlier versions, have been posted on security mailing list BugTraq and by eDvice. Aladdin Knowledge Systems has not published any advice to its users about the issue but has already come in for some flak from security experts.

Richard Stagg, senior consultant at Information Risk Management, said Aladdin was guilty of a "trivial and silly error" in allowing such a straightforward exploit to be successful.

Users of the software could be given a false sense of security, leaving them even more vulnerable to attack, he claimed. ®

External links

eDvice alert

Beginner's guide to SSL certificates

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.