2.2.12 Ensure HTTP Proxy Server is not enabled

Information

Squid is a standard proxy server used in many distributions and environments.

Rationale:

If there is no need for a proxy server, it is recommended that the squid proxy be deleted to reduce the potential attack surface.

Solution

Run the following command to disable squid:

# systemctl --now disable squid

Additional Information:

Additional methods of disabling a service exist. Consult your distribution documentation for appropriate methods.

On some distributions the squid service is known as squid3, not squid. Several HTTP proxy servers exist. These and other services should be checked.

See Also

https://workbench.cisecurity.org/files/2970

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: ee4e79df0b548ac3de649c8d51ecaa409275cf241b1d73a1b3396ebdd2428f19