id: open-proxy-external info: name: Open Proxy To External Network author: gtrrnr severity: medium description: The host is configured as a proxy which allows access to other hosts on the external network. remediation: Disable the proxy or restrict configuration to only allow access to approved hosts/ports. reference: - https://en.wikipedia.org/wiki/Open_proxy - https://www.acunetix.com/vulnerabilities/web/apache-configured-to-run-as-proxy/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N cvss-score: 5.8 cwe-id: CWE-441 metadata: max-request: 3 tags: exposure,config,proxy,misconfig http: - raw: - |+ GET https://test.s3.amazonaws.com HTTP/1.1 Host: test.s3.amazonaws.com - |+ GET http://{{interactsh-url}} HTTP/1.1 Host: {{interactsh-url}} - |+ GET / HTTP/1.1 Host: {{Hostname}} unsafe: true matchers-condition: and matchers: - type: dsl dsl: - contains_any(body_1, "", "") - contains(header_2, "X-Interactsh-Version") condition: and - type: dsl dsl: - '!contains(body_3, "")' - '!contains(header_3, "X-Interactsh-Version")' condition: and # digest: 4a0a00473045022036d712fd134d5c58821298c23404532ac0e933bd50c1cbba15c659a6c3874c9c022100edb90dfd6b0bae8c2d78bed811944d4bff8fb3b2855ba92e192c7042eec4a127:922c64590222798bb761d5b6d8e72950