HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.
It is currently 22 Jun 2014 09:53

All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: 21 Apr 2006 12:43 
Offline

Joined: 21 Apr 2006 11:30
Posts: 2
Hi, I'm tryin to open a html page which have a virus (and I know that :)
The problem is that I still want to get the info on page, but because of the virus havp blocked it at all.
Is possible anyway to get the rest of the page (so havp stop only suspicious and virus files - js,vbs.. etc.)?


Top
 Profile  
 
 Post subject:
PostPosted: 21 Apr 2006 12:51 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
It is not really possible, because everything we do is match patterns from some file, which happens to be a complete html-page in this case. It would require huge modifications if we wanted to actually modify the pages and remove javascript etc.. and since we only match patterns, actually we wouldn't even know what to remove to disinfect the page.

I don't know if using Privoxy would help in this case. It can detect some malicious javascript and remove it.

Cheers,
Henrik


Top
 Profile  
 
 Post subject:
PostPosted: 21 Apr 2006 12:58 
Offline

Joined: 21 Apr 2006 11:30
Posts: 2
thanks :)


Top
 Profile  
 
PostPosted: 27 May 2006 08:22 
If you really want to download the page, try getting it with a non-interpreting HTTP client like CURL. You can get the HTML into a text file and look at the it with a text editor to find what you want.


Top
  
 
 Post subject:
PostPosted: 27 May 2006 10:30 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
Naturally you would have to whitelist the page first..

Cheers,
Henrik


Top
 Profile  
 
PostPosted: 28 May 2006 04:21 
It obviously depends on the exact configuration, but I was more thinking of bypassing HAVP somehow. If you have multiple users, then whitelisting the page (even temporarily) could expose unsuspecting users to the virus.

It's likely to be harder to bypass HAVP if it is forcibly interposed on port 80 on the Internet gateway. On the other hand, if HAVP is listening on a different port, then it is easy to bypass (unless a firewall prevents it).


Top
  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Yahoo [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group