abuse of open transparent proxies

From: horape@tinuviel.compendium.net.ar
Date: 12/18/02

  • Next message: Ţórhallur Hálfdánarson: "Re: IRC -> smtp worm?"
    Date: Tue, 17 Dec 2002 23:58:29 -0300
    From: horape@tinuviel.compendium.net.ar
    To: incidents@securityfocus.com
    
    

    ˇHola!

    I don't know if this is new or not, but couldn't find anything about this
    when googling.

    I've just found an interesting attack against a friend's transparent proxy.

    The proxy was set up so that any connection to port 80 was proxied (no acl's)

    There is some spammer, herbal-place.com, using DNS views to exploit the proxy.

    To everybody but the proxy, it says that www.herbal-place.com's address is the
    proxy's one. To the proxy, it answers with their true IP.

    Result: my friend pay the bandwidth for the spammers.

    They have an automated system controlling this (30 seconds after we close the
    proxy they changed to abuse a new one)

    Saludos,
                                            HoraPe

    ---
    Horacio J. Peńa
    horape@compendium.com.ar
    horape@uninet.edu
    horape@hcdn.gov.ar
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    


    Relevant Pages

    • RE: Attempts to push spam through apache
      ... Attempts to push spam through apache ... Obviously this is an effort to pump spam through my server to 208.17.33.40. ... Are these just random spammer attempts to find an open proxy? ...
      (Focus-Linux)
    • Re: port scan?
      ... that a spammer is trying to exploit your computer, looking for a proxy ... or relay. ... I would be inclined to block all connections from 61.144.*.*. ...
      (comp.security.firewalls)
    • Re: AppScan and IDS evasion
      ... Isn't this a vulnerability in itself that your client blocks an IP ... This could result in a DoS attack if you can spoof source IP ... Since AppScan doesn't have any kind of IDS evasion, ... place some kind of proxy applying IDS-evasion techniques, ...
      (Pen-Test)
    • RE: Website search engine is a hacking tool..
      ... > and how can we mitigate the risk of using such techniques? ... >the local search engine as a proxy to attack other targets? ...
      (Pen-Test)
    • RE: [Full-Disclosure] Sidewinder G2
      ... > of someone configuring a rule wrong, ... This wasn't a root level attack on the Sidewinder host, ... through it via the transparent HTTP application proxy. ... version 4.1 failed to do actually do HTTP syntax checking making ...
      (Full-Disclosure)