Synopsis
The remote proxy can be used to connect to arbitrary ports
Description
The remote proxy, allows everyone to perform requests against arbitrary ports, such as :
'GET http://cvs.nessus.org:110'.
This problem may allow attackers to go through your firewall, by connecting to sensitive ports like 25 (sendmail) using the proxy. In addition to that, it might be used to perform attacks against other networks.
Solution
Set up ACLs in place to prevent your proxy from accepting to connect to non-authorized ports.
Plugin Details
File Name: proxy_port.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: Proxy/usage