|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
SafeWeb's web anonymizing service is supposed to anonymize the web surfing of its users. By analyzing the file sizes of requests, it is possible to glean information about the sites being visited. This attack can be used by a government to monitor which of its citizens are using SafeWeb to view seditious websites.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
SafeWeb
 |
Unknown or Unspecified |
|
|
|
|
Credit |
- Andrew Hintz - osvdb.web.drew
overt.org - http://guh.nu
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|