Security Basics mailing list archives
RE: socks 5
From: "Th@t Gurl" <undead001 () hotmail com>
Date: Sun, 21 Mar 2004 13:41:33 -0600
Hi,Socks 4 and 5 proxys are very usefull for people looking to bypass company firewalls. Basically if they can establish a connection to a remote socks proxy they can do anything the remote machine's connection allows(usually anything). For example, say your company doesn't allow icq. Someone brings a disk to work, installs icq and connects to a socks proxy. They can talk to anyone they want and the company firewall logs will only log the connections to the proxy host and not see where the connection is really going.
Its kinda hard for me to explain, as im not all that techy, but if your not filtering outgoing traffic to 1080 tcp then they can probably run about anything they want.
Socks 4 usually requires a userid Socks 5 usually requires a userid / password Hope this helps, Cassidy
From: "Kenzo" <kenzo_chin () hotmail com> To: <security-basics () securityfocus com> Subject: socks 5 Date: Thu, 18 Mar 2004 11:49:52 -0600 We have websense internet filter working with our Pix firewall to monitor web traffic.Today I noticed an attempted connection from our webserver to an external IPaddress using the socks 5 protocol. googling around I found out that socks 5 is used for some kind of remote access or authentication. I asked our webmaster and he has no Id what the remote IP address is. what could it be? did someone manage to own our box and using socks to bypass our firewall? Can anyone tell me more about socks? Thanks. --------------------------------------------------------------------------- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-fieldpen testing experience in our state of the art hacking lab. Master the skillsof an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ----------------------------------------------------------------------------
_________________________________________________________________MSN Toolbar provides one-click access to Hotmail from any Web page FREE download! http://clk.atdmt.com/AVE/go/onm00200413ave/direct/01/
---------------------------------------------------------------------------Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------
Current thread:
- socks 5 Kenzo (Mar 19)
- <Possible follow-ups>
- RE: socks 5 Th@t Gurl (Mar 22)
- RE: socks 5 Rivera Alonso, David (Mar 22)
- RE: socks 5 Shawn Jackson (Mar 23)
- RE: socks 5 Shawn Jackson (Mar 23)
- RE: socks 5 Rivera Alonso, David (Mar 23)