Attacking via CIM http 'proxies'

From: Kristian Franzen (kristian.franzen@trs.mine.nu)
Date: 02/19/02


Date: 19 Feb 2002 09:05:28 -0000
From: Kristian Franzen <kristian.franzen@trs.mine.nu>
To: pen-test@securityfocus.com


('binary' encoding is not supported, stored as-is)

All,

I'm currently testing a client of mine that have an
outdated version of Compaq Insight Manager
exposed to the Internet, thus allowing us to use it for
browsing internal webservers etc.

In an easy way, how do I make my non http proxy
aware tools and exploits utilize the proxy services
that CIM provides ? An approach that enable us to do
this, while not requiring us to rewrite each individual
tool and exploit for http proxy support would be sweat.

Ideas, anyone ?

/Kristian

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Vista. windows update wont even work!
    ... I have all update sites bypassing our HTTP proxy and have toggled ... Customers in the U.S. and Canada can receive technical support from Microsoft Product ... You regularly suggest this Rediness tool as ...
    (microsoft.public.windowsupdate)
  • Re: [Full-disclosure] Internet Explorer 0day
    ... You mean like when they added basic HTTP CONNECT back in October of 2004? ... "Add support for the HTTP proxy CONNECT method to nc." ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)