I am getting an unexpected security hole report from proxy_port.nasl
(The proxy, allows everyone to perform requests against arbitrary
ports, like 'GET http://cvs.nessus.org:110'. This problem may
allow attackers to go through your firewall, by connecting to
sensitive ports like 25 (sendmail) using your proxy. In addition
to that, your proxy may be used to perform attacks against other
networks.)
I assume this could occur because the proxy is not responding with
correct error codes, just a text error message?
If not, how can I verify/demonstrate the hole?
--
Matt Whelan <[EMAIL PROTECTED]>