141
Cerbere HTTP Proxy prior 1.2 HTTP Host field Denial of Service
Firewalls
2004/09/03
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.1. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send GET http://www.computec.ch HTTP/1.0\nProxy-Connection: Keep-Alive\n\n|sleep|close|pattern_exists HTTP/#.# ### *Cerbère Proxy Server r*0* OR HTTP/#.# ### *Cerbère Proxy Server r*1.[0-2]*
80
This plugin was written with the ATK Attack Editor and it is inspired by the Nessus plugin.
Cerbere HTTP Proxy prior 1.2
Cerbere HTTP Proxy newer than 1.2 or other proxy servers
Buffer Overflow
A Cerbere HTTP proxy server prior 1.2 seems to be running or proxying the web requests. This version is vulnerable to a denial of service attack in the Host:-field. An attacker may craft a malicious HTTP request with a large field to deny service to legetimate users.
Upgrade to the latest version of this software and firewall unwanted requests or install another proxy solution.
Approx. 30 minutes
Maybe
http://www.securityfocus.com/bid/11085/exploit/
Yes
Yes
Medium
7
8
8
7
Medium
Nessus is able to do the same check.
11085
14640
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch