Re: Tool to find hidden web proxy server

From: Gary E. Miller (gem_at_rellim.com)
Date: 09/02/04

  • Next message: Jose Maria Lopez: "RE: Craking Serv-u passwords stored in .ini file."
    Date: Thu, 2 Sep 2004 09:34:25 -0700 (PDT)
    To: vinay mangal <vinay.mangal@eil.co.in>
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Yo Vinay!

    No reason the proxy has to be INSIDE your firewall. All a user needs is
    SSH, OpenVPN, or similar. Then they can set up an encrypted tunnel
    from the local workstation to an external proxy or tunnel gateway.

    If the guy setting it up is smart you will have to dig him out the hard
    way. Set up tcpdump or ethereal on your internet gateway. Do
    a capture of ALL the traffic, then go throught it all, eliminate the
    "good" traffic and what is left is the "problem" traffic.

    If they are good they can tunnel using DNS/udp or even an IP that is not
    TCP, UDP or ICMP. If they are truly devious they could use Wi-Fi or
    Cell Phones to just bypass your firewall completely.

    The best way to catch them is to carry a 2x4 and do some MBWA (Management
    By Walking Around). Fire the first guy you catch and the problem will
    greatly diminish.

    RGDS
    GARY
    - ---------------------------------------------------------------------------
    Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701
            gem@rellim.com Tel:+1(541)382-8588 Fax: +1(541)382-8676

    On Thu, 2 Sep 2004, vinay mangal wrote:

    > This problem is strictly with in company internet access firewall and in the
    > LAN only. In a company, policy for Internet access says it is through IP
    > only. The others can not browse the internet. This policy is implemented on
    > firewall. Few smart guys have installed free proxy server running on non
    > default ports and distributed the internet access to their friends. The
    > firewall sees the traffic coming from the authorized IP and does not stop
    > them. We want to know who has installed proxy on there machine.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)

    iD8DBQFBN0uT8KZibdeR3qURAoWvAJ96HjjPr/52Y/YpAkopxw7sBOP+lQCgqJ8l
    ZautnaCB4q+WprFinOTY/To=
    =wHh+
    -----END PGP SIGNATURE-----

    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one interaction
    with one of our expert instructors. Check out our Advanced Hacking course,
    learn to write exploits and attack security infrastructure. Attend a course
    taught by an expert instructor with years of in-the-field pen testing
    experience in our state of the art hacking lab. Master the skills of an
    Ethical Hacker to better assess the security of your organization.

    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------


  • Next message: Jose Maria Lopez: "RE: Craking Serv-u passwords stored in .ini file."

    Relevant Pages

    • Re: [fw-wiz] dirty packet tricks?
      ... solve via promiscuously sucking up packets. ... restriction that your 'sideways' proxy box is it will have to be on a hub ... The firewall will have to suppress all ICMP errors to the internal network ...
      (Firewall-Wizards)
    • Re: [fw-wiz] httport 3snf
      ... >> wouldn't have gotten SSH out of my firewall. ... > Postfix SMTP server with a wildcard MX that handed the mail that wasn't ... > destined to me off to the downstream MS stuff, and an HTTP proxy server ... All it needs is a written policx "Internet access is ...
      (Firewall-Wizards)
    • Re: Kids bypassing firewall via web proxy sites
      ... We use a Sonicwall firewall, 3060, I subscribe to content fltering, ... I checked "Access to HTTP Proxy Servers" But I am still able to get to ... CyBlock, which does network proxy and filtering ...
      (comp.security.firewalls)
    • Re: NAT is not a mechanism for securing a network.. but.. HELP!
      ... tell you a NAT router is a firewall. ... > There is this one hot chick at a major American news network, ... >proxy, and come to a chat room where her and I have been chatting, she has ... >admins at the station she works for. ...
      (comp.security.firewalls)
    • 0xc0040017 FWX_E_TCP_NOT_SYN_PACKET_DROPPED bei 2 Servern von 6
      ... Server Windows 2008 Std ML350 mit installiertem Hyper-V und entsprechenden virtuellen Maschinen. ... Log Time Client IP Destination IP Destination Port Protocol Action Rule Client Username Source Network Destination Network HTTP Method URL Error Information HTTP Status Code Original Client IP Client Agent Authenticated Client Service Server Name Referring Server Destination Host Name Transport MIME Type Object Source Source Proxy Destination Proxy Bidirectional Client Host Name Filter Information Network Interface Raw IP Header Raw Payload GMT Log Time Source Port Processing Time Bytes Sent Bytes Received Result Code Cache Information Log Record Type Authentication Server ... Unrestricted Internet access anonymous Internal External HEAD ...
      (microsoft.public.de.german.isaserver)