Penetration Testing mailing list archives
RE: check the presence of a reverse proxy
From: "Marchand, Tom" <Tom.Marchand () bcbsfl com>
Date: Tue, 30 Nov 2004 17:14:01 -0500
To check for a reverse proxy can you fingerprint the network traffic fingerprint the http headers and compare them? This might find situations where you have a webserver that is running on a different platform than the proxy. For example: IIS behind a squid proxy running on linux. -----Original Message----- From: Maria Da Re [mailto:pentestml () yahoo it] Sent: Tuesday, November 30, 2004 4:16 PM To: pen-test () securityfocus com Subject: check the presence of a reverse proxy Can i check the presence of a reverse proxy between me and some webservers? The pen-test scenario (target network) is: - 2 level of firewall (pix and iptables) - one dmz with a squid configured as reverse proxy (and other things) - one internal network with 4 webserver with apache and public ip address (and other things) So i would to check if my request to one of webserver is natted (by external firewall) to the proxy and redirected by the proxy to the webserver. I can work from Internet, from a subnet connected to external firewall, from a subnet connected to internal firewall. Some suggestions? Many thanks m. ___________________________________ Nuovo Yahoo! Messenger: E' molto piĆ¹ divertente: Audibles, Avatar, Webcam, Giochi, Rubrica... Scaricalo ora! http://it.messenger.yahoo.it Blue Cross Blue Shield of Florida, Inc., and its subsidiary and affiliate companies are not responsible for errors or omissions in this e-mail message. Any personal comments made in this e-mail do not reflect the views of Blue Cross Blue Shield of Florida, Inc. The information contained in this document may be confidential and intended solely for the use of the individual or entity to whom it is addressed. This document may contain material that is privileged or protected from disclosure under applicable law. If you are not the intended recipient or the individual responsible for delivering to the intended recipient, please (1) be advised that any use, dissemination, forwarding, or copying of this document IS STRICTLY PROHIBITED; and (2) notify sender immediately by telephone and destroy the document. THANK YOU.
Current thread:
- RE: check the presence of a reverse proxy Marchand, Tom (Dec 01)
- RE: check the presence of a reverse proxy Maria Da Re (Dec 02)
- <Possible follow-ups>
- Re: check the presence of a reverse proxy hvjuan (Dec 01)
- Re: check the presence of a reverse proxy rlpentest (Dec 01)
- Re: check the presence of a reverse proxy Cedric Foll (Dec 01)
- Re: check the presence of a reverse proxy H D Moore (Dec 02)
- Re: check the presence of a reverse proxy joe star (Dec 07)