Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

abuse of open transparent proxies

From: <horape(at)tinuviel.compendium.net.ar>
Date: Tue Dec 17 2002 - 21:58:29 EST


¡Hola!

I don't know if this is new or not, but couldn't find anything about this when googling.

I've just found an interesting attack against a friend's transparent proxy.

The proxy was set up so that any connection to port 80 was proxied (no acl's)

There is some spammer, herbal-place.com, using DNS views to exploit the proxy.

To everybody but the proxy, it says that www.herbal-place.com's address is the proxy's one. To the proxy, it answers with their true IP.

Result: my friend pay the bandwidth for the spammers.

They have an automated system controlling this (30 seconds after we close the proxy they changed to abuse a new one)

Do you need help?X

Saludos,

                                        HoraPe

---
Horacio J. Peņa
horape@compendium.com.ar
horape@uninet.edu
horape@hcdn.gov.ar

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: 
http://aris.securityfocus.com
Received on Wed Dec 18 10:59:51 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:54 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library