Search squid archive

Re: Squid 3.2.1 is available

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Downloaded the source from JP mirror and compiled.
Works like a charm with http interception and http cache_peer.

On 8/15/2012 2:29 PM, Amos Jeffries wrote:
  * CVE-2009-0801 : NAT interception vulnerability to malicious clients.
about this "bug" i tried to read about it just of curiosity but i didnt understood the actual vulnerability.
in the bugzilla it states:
##start
Due to Squid not reusing the original destination address on intercepted
requests it's possible (even trivial) for flash or java applets to bypass the
same-origin policy in the browser when Squid intercepts HTTP requests.

The cause to this is that such applets are allowed to perform their own HTTP
stack, in which case the same-origin policy of the browser sandbox only
verifies that the applet tries to contact the same IP as from where it was
loaded at the IP level. Squid then uses the Host header to determine which
server to forward the request to which may be different from the connected IP.

Applies to all Squid releases.
##end

well this is the basic expected behavior of a proxy to verify the destination host and NAT interception.

even if the destination IP is not the same as the connected one it still validates the same host\domain so what is the problem?

Thanks,
Eliezer

--
Eliezer Croitoru
https://www1.ngtech.co.il
IT consulting for Nonprofit organizations
eliezer <at> ngtech.co.il


[Index of Archives]     [Linux Audio Users]     [Samba]     [Big List of Linux Books]     [Linux USB]     [Yosemite News]

  Powered by Linux