HTTP Proxy CONNECT Request Relaying

This script is Copyright (C) 1999-2016 Tenable Network Security, Inc.


Synopsis :

An HTTP proxy running on the remote host can be used to establish
interactive sessions.

Description :

The proxy allows users to perform CONNECT requests such as :

CONNECT http://cvs.example.org:23

This request gives the person who made it the ability to have an
interactive session with a third-party site.

This issue may allow attackers to bypass your firewall by connecting
to sensitive ports such as 23 (telnet) via the proxy, or it may allow
internal users to bypass the firewall rules and connect to ports or
sites they should not be allowed to.

In addition, your proxy may be used to perform attacks against other
networks.

Solution :

Reconfigure your proxy to refuse CONNECT requests.

Risk factor :

None

Family: Firewalls

Nessus Plugin ID: 10192 ()

Bugtraq ID:

CVE ID:

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial