32
Proxy POST port tcp/21 detection
Firewalls
2003/11/14
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.3. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send POST http://www.computec.ch:21/ HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 *
90
This plugin was written with the ATK Attack Editor.
Some web proxies
Configuration
Some proxies allow interactive connections to not directly supported ports with an POST request without content-length tag.
Reconfigure your proxy so that only the users of the internal network can use it, and so that it can not connect to dangerous ports (0-1023).
20 minutes
Yes
Yes
Yes
High
8
7
7
7
High
Nessus is able to do the same check.
10194
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch