HTTP Proxy CONNECT Request Relaying

This script is Copyright (C) 1999-2016 Tenable Network Security, Inc.

Synopsis :

An HTTP proxy running on the remote host can be used to establish
interactive sessions.

Description :

The proxy allows users to perform CONNECT requests such as :


This request gives the person who made it the ability to have an
interactive session with a third-party site.

This issue may allow attackers to bypass your firewall by connecting
to sensitive ports such as 23 (telnet) via the proxy, or it may allow
internal users to bypass the firewall rules and connect to ports or
sites they should not be allowed to.

In addition, your proxy may be used to perform attacks against other

Solution :

Reconfigure your proxy to refuse CONNECT requests.

Risk factor :


Family: Firewalls

Nessus Plugin ID: 10192 ()

Bugtraq ID:


Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now