On Sat, Mar 16, 2002 at 12:44:36AM +1100, Matt Whelan wrote:
> I am getting an unexpected security hole report from proxy_port.nasl
> 
>      (The proxy, allows everyone to perform requests against arbitrary
>      ports, like 'GET http://cvs.nessus.org:110'.  This problem may
>      allow attackers to go through your firewall, by connecting to
>      sensitive ports like 25 (sendmail)  using your proxy. In addition
>      to that, your proxy may be used to perform attacks against other
>      networks.)
> 
> I assume this could occur because the proxy is not responding with
> correct error codes, just a text error message?

It *may* be a real problem. Try the following :

telnet into the host_in_question port_in_question
type :

        GET http://mail.nessus.org:25/ HTTP/1.1
        Host: mail.nessus.org


And type "return" twice
(you can replace mail.nessus.org by other mail server you want to use,
of course).

And see what result you get (if you see the SMTP banner somewhere,
the host is a proxy).

                                -- Renaud

Reply via email to