RE: check the presence of a reverse proxy

From: Marchand, Tom (Tom.Marchand_at_bcbsfl.com)
Date: 11/30/04

  • Next message: Anders Thulin: "Re: Netscape Ldap ldif file SHA password cracking"
    Date: Tue, 30 Nov 2004 17:14:01 -0500
    To: pen-test@securityfocus.com
    
    

    To check for a reverse proxy can you fingerprint the network traffic fingerprint the http headers and compare them? This might find situations where you have a webserver that is running on a different platform than the proxy. For example: IIS behind a squid proxy running on linux.

    -----Original Message-----
    From: Maria Da Re [mailto:pentestml@yahoo.it]
    Sent: Tuesday, November 30, 2004 4:16 PM
    To: pen-test@securityfocus.com
    Subject: check the presence of a reverse proxy

    Can i check the presence of a reverse proxy
    between me and some webservers?

    The pen-test scenario (target network) is:

    - 2 level of firewall (pix and iptables)
    - one dmz with a squid configured as reverse proxy
    (and other things)
    - one internal network with 4 webserver with apache
    and public ip address (and other things)

    So i would to check if my request to one of webserver
    is natted (by external firewall) to the proxy and
    redirected by the proxy to the webserver. I can work
    from Internet, from a subnet connected to external
    firewall, from a subnet connected to internal
    firewall.

    Some suggestions?

    Many thanks

    m.

                    
    ___________________________________
    Nuovo Yahoo! Messenger: E' molto pił divertente: Audibles, Avatar, Webcam, Giochi, Rubrica... Scaricalo ora!
    http://it.messenger.yahoo.it

    Blue Cross Blue Shield of Florida, Inc., and its subsidiary and affiliate companies are not responsible for errors or omissions in this e-mail message. Any personal comments made in this e-mail do not reflect the views of Blue Cross Blue Shield of Florida, Inc. The information contained in this document may be confidential and intended solely for the use of the individual or entity to whom it is addressed. This document may contain material that is privileged or protected from disclosure under applicable law. If you are not the intended recipient or the individual responsible for delivering to the intended recipient, please (1) be advised that any use, dissemination, forwarding, or copying of this document IS STRICTLY PROHIBITED; and (2) notify sender immediately by telephone and destroy the document. THANK YOU.


  • Next message: Anders Thulin: "Re: Netscape Ldap ldif file SHA password cracking"

    Relevant Pages

    • Re: How to secure a webserver in a DMZ
      ... If your webserver gets comprised, your DB is open as well. ... How easy would it be for an "advanced agressor" to load evil code (for ssh-over-https-tunneling i.e.) from the internet, if the only connection to the webserver is encrypted http inbound and outbound traffic is not allowed? ... If anybody was able to compromise the Reverse proxy over https, than he could even go further and compromise the backand webserver through tricky-http stuff also? ...
      (Security-Basics)
    • check the presence of a reverse proxy
      ... Can i check the presence of a reverse proxy ... The pen-test scenario (target network) is: ... - 2 level of firewall ... So i would to check if my request to one of webserver ...
      (Pen-Test)
    • Re: check the presence of a reverse proxy
      ... > - one dmz with a squid configured as reverse proxy ... > redirected by the proxy to the webserver. ... > from Internet, from a subnet connected to external ... > firewall, from a subnet connected to internal ...
      (Pen-Test)
    • Re: which firewall
      ... Take a reverse proxy. ... This will at least ensure syntactically correct questions to the webserver ... IIS as webserver is bad, if you can reach it directly,) ...
      (comp.security.firewalls)
    • Re: which firewall
      ... Take a reverse proxy. ... This will at least ensure syntactically correct questions to the webserver ... IIS as webserver is bad, if you can reach it directly,) ...
      (comp.security.firewalls)