2.2.14 Ensure HTTP Proxy Server is not enabled

Information

Squid is a standard proxy server used in many distributions and environments.

Rationale:

If there is no need for a proxy server, it is recommended that the squid proxy be deleted to reduce the potential attack surface.

Solution

Run the following command to disable squid :

# systemctl disable squid

Notes:

Additional methods of disabling a service exist. Consult your distribution documentation for appropriate methods.

On some distributions the squid service is known as squid3, not squid. Several HTTP proxy servers exist. These and other services should be checked.

See Also

https://workbench.cisecurity.org/files/2688

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 81f2e67e58edcf37441cf1d6cf30cdfcb5a668f575297824b0c6ef906f77c485