the
last post was
about a fuse filesystem which provides a read-only access to the proprietary
bluecoat filesystem. After some further investigations based on the
possibilities this offered us, I started to implement a tool which allows to
modify parts of the filesystem.
Protection Mechanisms
Since last time, the discovered filesystem structures still had unknown fields.
Some of those fields could be reconstructed and their purpose in the whole
construct. The format of the Partition-Header for example could now be
described as
You may remember
our last post regarding
the SGOS system and the proprietary file system. Since then, we got access to a
newer version of the system (6.6.4.2). Still not the most current one (which
seems to be 6.7.1.1) nor of the 6.6.x branch (which seems to be 6.6.5.1) though.
As this system version also used the same proprietary filesystem (although it
initially booted from a FAT32 partition), I decided to take a deeper look into
this.
As a part of our research time here at ERNW, last week we had an interesting
time looking at one of the widespread and commonly adopted proxy appliance by
many organizations Blue Coat Secure Gateway.
Introduction
The Blue Coat proxy Secure Gateway (SG) has been already in the market since
2001 [1]. The main aim of introducing the appliance was to achieve the
following goals [2]:
• High performance optimization.
• Increasing the security measurements, by introducing malware/spyware
protections, web based filtering, virus scanning and more.
• Flexible Access Control capabilities.