Proxy/Firewall Detection with PVS
by John Lampe on October 8, 2006
During the past year, the Passive Vulnerability Scanner's rules were modified to detect network proxies and firewalls. This process also involved the reduction of reporting multiple browser types for different hosts running behind a NAT device or proxy.
As an example, what happens if PVS (or any sniffer, IDS, etc.) see's the following string in a packet leaving the network?