HTTP: BadBlue Proxy Relay

This signature detects attempts to relay a Web request through a BadBlue Web server. When BadBlue is using its default configuration, attackers can use the Web server as a proxy server to attack internal targets or mask attack activity.

Extended Description

A vulnerability exists in the way that BadBlue web server does not use authorization when specially crafted proxy requests are received by it. Attackers could exploit this vulnerability to bypass firewalls and compromise other servers using BadBlue as a proxy.

Short Name
HTTP:BADBLUE:PROXY-RELAY
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
BadBlue Proxy Relay
Release Date
08/18/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?