197 HTTP Proxy connect method detection Firewalls 2004/09/09 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.1 Corrected the plugin structure and added the accuracy values in 1.1 tcp 8080 open|send CONNECT www.computec.ch:21 HTTP/1.0\n\n|sleep|close|pattern_exists 200 OR 503 90 This plugin was written with the ATK Attack Editor. Misconfigured or unsecure HTTP proxy servers Other solutions Configuration This problem may allow attackers to go through your firewall, by connecting to sensitive ports like 23 (telnet) using your proxy, or it can allow internal users to bypass the firewall rules and connect to ports they should not be allowed to. In addition to that, your proxy may be used to perform attacks against other networks. You should install or upgrade the proxy to the latest version to prevent the exploitation of known vulnerabilities. Also limit unwanted connections and communications with ACL and firewalling. Approx. 40 minutes Yes Yes Yes High 7 6 7 7 High Nessus is able to do the same check. 10192 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch