BugTraq
Apache 1.3.27 mod_proxy security issue Jul 22 2003 04:52PM
Jason Robertson (jason ifuture com) (1 replies)
I have found that recently a spammer has been using a mod_proxy
configuration, (that was meant to allow for an easier transition to a
new naming scheme, as well as changes to a backend software) as a spam
relay.
The spammer has been using HTTP POST requests to send these messages
with POST HTTP://mailserver:25/ HTTP/1.1
With some research it looks like this is an automated process including
the initial scan stage.

When I contacted Apache in regards to this, the response was not very
promising.

This problem would be a simple fix with implementing the AllowConnect
configuration option within proxy_http, to prevent outbound
connections.

Jason

[ reply ]
Re: Apache 1.3.27 mod_proxy security issue Jul 22 2003 10:30PM
William A. Rowe, Jr. (wrowe apache org) (1 replies)
Re: Apache 1.3.27 mod_proxy security issue Jul 29 2003 09:34AM
Michael Shigorin (mike osdn org ua) (1 replies)
Re: Apache 1.3.27 mod_proxy security issue Jul 29 2003 08:36PM
William A. Rowe, Jr. (wrowe apache org) (1 replies)
Re: Apache 1.3.27 mod_proxy security issue Jul 29 2003 09:01PM
Joshua Slive (joshua slive ca)


 

Privacy Statement
Copyright 2010, SecurityFocus