Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Fifteen-year-old server-side bug opens up websites
iTnews (AUS) ^ | Jul 19 2016 6:08AM (AUS) | Juha Saarinen

Posted on 07/18/2016 5:37:21 PM PDT by Utilizer

A remotely exploitable vulnerability in web application code, first discovered 15 years ago, has returned to haunt server admins who are being urged to take action immediately to avoid being hit.

Researchers from New Zealand point of sale software company Vend, Dominic Scheirlink, Richard Rowe, Morgan Pyne and Scott Geary, worked with Red Hat product security staffer Kurt Seifried to document the flaw, which they have nicknamed Httpoxy.

On vulnerable applications, the Httpoxy flaw is easily exploitable, the researchers said.

Attackers can proxy outgoing HTTP requests and direct the server to open outwards connections to arbitrary IP addresses and transport control protocol (TCP) ports.

The flaw also allows for denial of service attacks, by forcing vulnerable software to use a malicous proxy to tie up server resources.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: bug; httpoxy; internet; php; security; server
Server and PHP scripting security flaw, it appears.
1 posted on 07/18/2016 5:37:21 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

Ping...


2 posted on 07/18/2016 5:38:27 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; Swordmaker

You might be interested in this one...


3 posted on 07/18/2016 5:39:33 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

...as well (I forgot to add).


4 posted on 07/18/2016 5:40:09 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

https://www.nginx.com/blog/mitigating-the-httpoxy-vulnerability-with-nginx/


5 posted on 07/18/2016 6:04:44 PM PDT by Ray76 (The evil effect of Obergefell is to deprive the people of rule of law & subject us to tyranny!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ray76

Great link! I strongly recommend you start a thread about it, mate. I believe it warrants more exposure.

Cheers!


6 posted on 07/18/2016 6:11:31 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Utilizer; ShadowAce
> You might be interested in this one...

Even more, ShadowAce, our Linux listkeeper.

https://httpoxy.org/

Apache:
1. Enable mod_headers (however done in the config)
2. RequestHeader unset Proxy early
https://www.apache.org/security/asf-httpoxy-response.txt

IIS:
appcmd set config /section:requestfiltering
/+requestlimits.headerLimits.[header='proxy',sizelimit='0']
https://support.microsoft.com/en-us/kb/3179800

Drupal:
https://www.drupal.org/PSA-2016-002

7 posted on 07/21/2016 2:47:26 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson