« C0mrade's Suicide Linked to TJX Probe | Main | Antisec hackers replace all imageshack images! »

Months later, more products identified using exploitable transparent proxy architecture

It's been more than 3 months since I published my paper on abusing transparent proxies with flash, and 4 months since CERT's Advisory (VU#435052). Since that time additional products have been identified as being exploitable.


Still Vulnerable


Products with fixes or workarounds

Note: I have not verified the claimed fixes for the products above and have no plans to.

As you can see a number of security web filtering products are open to abuse. Some vendors provide a workaround involving 'filtering off IP' to sensitive internal addresses' which isn't a fix for this issue because you can still make any request to any outside network (assuming the proxy supports this, most will).

Chances are there are dozens more affected since this is a design abuse. If you know any please let me know and I'll add it to the list (please include something from the vendor page acknowledging the issue).

I'll be attending Blackhat and defcon later this month so if there are any proxy/http nerds who want to chat drop me a line.


Additional Coverage and related posts

Socket Capable Browser Plug-ins Result In Transparent Proxy Abuse
http://www.cgisecurity.com/2009/03/socket-capable-browser-plugins-result-in-transparent-proxy-abuse.html

Proxy Attack Stupid Buzzword Contest
http://www.cgisecurity.com/2009/03/proxy-attack-stupid-buzzword-contest-.html

Why does Silverlight have a restricted port range for Sockets?
http://blogs.msdn.com/ncl/archive/2009/06/23/why-does-silverlight-have-a-restricted-port-range-for-sockets.aspx

Proxy server bug exposes websites' private parts
http://www.theregister.co.uk/2009/02/23/serious_proxy_server_flaw/

ISA Server vs US-CERT VU#435052 – A Quick Test
http://www.carbonwind.net/blog/post/2009/03/21/ISA-Server-vs-US-CERT-VU435052-e28093-A-Quick-Test.aspx

Transparente Proxies ebnen Angreifern den Weg ins lokale Netz
http://www.heise.de/netze/Transparente-Proxies-ebnen-Angreifern-den-Weg-ins-lokale-Netz--/news/meldung/134333

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.


All Comments are Moderated and will be delayed!


Post a comment







Remember personal info?