RE: Weird log entries...

From: Cushing, David (David.Cushing@hitachisoftware.com)
Date: 03/28/02


Date: Thu, 28 Mar 2002 09:25:13 -0500
From: "Cushing, David" <David.Cushing@hitachisoftware.com>
To: "Josh Diakun" <joshd@superaje.com>, "Incidents" <INCIDENTS@SECURITYFOCUS.COM>

Josh,

It's not a bug, it's a feature. The connect command is used to do what
you guessed: create a tunnel to another location.

http://www.ietf.org/rfc/rfc2817.txt

5.2 Requesting a Tunnel with CONNECT

A CONNECT method requests that a proxy establish a tunnel connection
on its behalf. The Request-URI portion of the Request-Line is always
an 'authority' as defined by URI Generic Syntax [2], which is to say
the host name and port number destination of the requested connection
separated by a colon:

   CONNECT server.example.com:80 HTTP/1.1
   Host: server.example.com:80

Obviously, if you have a program that supports this feature, it should
be locked down!

-David

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: The C Boolean Fallacy Crack
    ... Just requesting including a biography on behalf of the tunnel is too ... mathematical for Anastasia to laugh it. ...
    (sci.crypt)
  • Re: known Java frame, how to get handle to a edit control box?
    ... > particular key was pressed and thereby limit the callback execution to ... And I was requesting this ... Java to do the feature I've requested, ... I am seeking help here to get around that problem in Matlab. ...
    (comp.lang.java.help)
  • Re: putty question - port forwarding on a machine where I have no shell access
    ... > without requesting a shell channel (e.g. like the -N option to ... Quite a lot of the features on the PuTTY wishlist are there because ... poster would like to see this feature in PuTTY ...
    (comp.security.ssh)
  • Re: Office 2003
    ... beleived it was a "feature" of Word.... ... >> We just installed Office 2003 on campus and users are requesting we ...
    (microsoft.public.office.misc)
  • Re: qGo 1.0.3 released
    ... Are you requesting a 'save' feature or an 'autosave' feature? ... Because you could already save your own games with the 'File / Save' menu. ...
    (rec.games.go)