HTTP: SMTP Proxied Through HTTP

This signature detects attempts to connect to an SMTP server through an HTTP CONNECT. Some HTTP servers allow to proxy to other services. Spammers use improperly configured HTTP servers to forward spam e-mails to avoid black lists.

Extended Description

Multiple software and integrated server packages that function as web proxies may be used as open TCP proxies. This is through the usage of the HTTP CONNECT method by default. This method is detailed in RFC 2817, where it is used to build generic Transit Layer Security over HTTP. Upon receiving a CONNECT request, vulnerable products act as a TCP proxy, tunneling the conversation. This can be used to launch attacks against internal machines or to, for example, use an internal mail server as an open relay. In many cases, this behavior may be controlled through the server configuration. Often it is related to support for tunneling or SSL related functionality. The issue may also introduce an additional threat. Trusted, internal hosts may be able to proxy unauthorized connections to arbitrary ports on external hosts, which may violate security policy. This vulnerability represents a preliminary list of vendors which may have vulnerable default configurations. Updates will be made as additional information becomes available.

Affected Products

Cacheflow cacheos,Lotus domino,Sambar server

Short Name
HTTP:TUNNEL:SMTP
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
HTTP Proxied SMTP Through bid:4131
Release Date
10/17/2006
Supported Platforms

srx-branch-12.3

srx-branch-19.3

vsrx3bsd-19.2

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-19.3

srx-12.3

Sigpack Version
3794
False Positive
Unknown
Vendors

Csm

Netcplus

W3c

Astaro

Trend_micro

Deerfield.com

Acme_software

Nec

Intergate

Compusource_(pty)_ltd

Network_associates

Analogx

Etype

Boramae

Netapp

Ncsa

Apache_software_foundation

Imatix

Check_point_software

Omnicron

Ascenvision

Microsoft

Httptunnel_client

Novell

Liteserve

Netscape

Avirt

Ibm

Allegrosurf

Internet_factory

Tinyproxy

Sonicwall

Grok_developments

Delegate

Symantec

Cacheflow

National_science_foundation

Unitech_networks

Jana_server

Sambar

Filemaker

Lotus

Pronetix_ltd.

Korea_network_intelligence

Argo_software_design

Finjan

Mywebserver

Inmon

Ipswitch

Medusa

Adtran

Pi-soft

Found a potential security threat?