Security Basics mailing list archives

RE: socks 5


From: "Th@t Gurl" <undead001 () hotmail com>
Date: Sun, 21 Mar 2004 13:41:33 -0600

Hi,

Socks 4 and 5 proxys are very usefull for people looking to bypass company firewalls. Basically if they can establish a connection to a remote socks proxy they can do anything the remote machine's connection allows(usually anything). For example, say your company doesn't allow icq. Someone brings a disk to work, installs icq and connects to a socks proxy. They can talk to anyone they want and the company firewall logs will only log the connections to the proxy host and not see where the connection is really going.

Its kinda hard for me to explain, as im not all that techy, but if your not filtering outgoing traffic to 1080 tcp then they can probably run about anything they want.

Socks 4 usually requires a userid
Socks 5 usually requires a userid / password

Hope this helps,
Cassidy




From: "Kenzo" <kenzo_chin () hotmail com>
To: <security-basics () securityfocus com>
Subject: socks 5
Date: Thu, 18 Mar 2004 11:49:52 -0600

We have websense internet filter working with our Pix firewall to monitor
web traffic.
Today I noticed an attempted connection from our webserver to an external IP
address using the socks 5 protocol.
googling around I found out that socks 5 is used for some kind of remote
access or authentication.
I asked our webmaster and he has no Id what the remote IP address is.
what could it be? did someone manage to own our box and using socks to
bypass our firewall?
Can anyone tell me more about socks?

Thanks.

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


_________________________________________________________________
MSN Toolbar provides one-click access to Hotmail from any Web page – FREE download! http://clk.atdmt.com/AVE/go/onm00200413ave/direct/01/


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: