I am getting an unexpected security hole report from proxy_port.nasl

     (The proxy, allows everyone to perform requests against arbitrary
     ports, like 'GET http://cvs.nessus.org:110'.  This problem may
     allow attackers to go through your firewall, by connecting to
     sensitive ports like 25 (sendmail)  using your proxy. In addition
     to that, your proxy may be used to perform attacks against other
     networks.)

I assume this could occur because the proxy is not responding with
correct error codes, just a text error message?

If not, how can I verify/demonstrate the hole?

-- 
Matt Whelan <[EMAIL PROTECTED]>

Reply via email to