HTTP Proxy Open Relay Detection

info Nessus Plugin ID 10195

Synopsis

The remote web proxy server accepts requests.

Description

The remote web proxy accepts unauthenticated HTTP requests from the Nessus scanner. By routing requests through the affected proxy, a user may be able to gain some degree of anonymity while browsing websites, which will see requests as originating from the remote host itself rather than the user's host.

Solution

Make sure access to the proxy is limited to valid users / hosts.

Plugin Details

Severity: Info

ID: 10195

File Name: proxy_use.nasl

Version: Revision: 1.42

Type: remote

Family: Firewalls

Published: 6/22/1999

Updated: 4/25/2014

Supported Sensors: Nessus