HTTP_PROXY Traffic Redirection

July 22, 2016

Common Gateway Interface (CGI) allows server side scripts to handle client HTTP request through platform independent interface. CGI rules and guidelines are defined in RFC 3875. HTTP is request/response protocol. Client HTTP requests are handled and responded by server. This vulnerability affects application code running in CGI, or CGI-like environments.

HTTP_PROXY is a popular environment variable used to configure an outgoing proxy. Upon receiving request with the Proxy HTTP header, Vulnerable server sets the $HTTP_PROXY environment variable to the value of Proxy HTTP header. Attackers can set the HTTP_PROXY environment variable using the malicious Proxy HTTP header. This allows remote attacker to launch a man-in-the-middle attack by redirecting traffic through controlled proxy.

Dell SonicWALL has researched this vulnerability. The following signature has been created to protect their customers.

  • IPS: 11749 Suspicious HTTP Proxy Header 1