Security Basics mailing list archives

RE: socks 5


From: "Rivera Alonso, David" <drivera () iberdrola es>
Date: Mon, 22 Mar 2004 11:34:11 +0100


Socks is a protocol to build kind of tunnels for TCP/IP applications:

Check this site to learn more:
http://www.socks.permeo.com/AboutSOCKS/SOCKSOverview.asp

regards from Spain,

DAVID

-----Mensaje original-----
De: Kenzo [mailto:kenzo_chin () hotmail com] 
Enviado el: jueves, 18 de marzo de 2004 18:50
Para: security-basics () securityfocus com
Asunto: socks 5


We have websense internet filter working with our Pix firewall to monitor
web traffic.
Today I noticed an attempted connection from our webserver to an external IP
address using the socks 5 protocol.
googling around I found out that socks 5 is used for some kind of remote
access or authentication.
I asked our webmaster and he has no Id what the remote IP address is.
what could it be? did someone manage to own our box and using socks to
bypass our firewall?
Can anyone tell me more about socks?

Thanks.

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the
skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------




=============================
Este mensaje se dirige exclusivamente a su destinatario.
Puede contener informacion confidencial sometida a secreto profesional o cuya divulgacion
este prohibida, en virtud de la legislacion vigente. No esta permitida su divulgacion,
copia o distribucion a terceros sin la autorizacion previa y por escrito de Iberdrola.
Si ha recibido este mensaje por error, le rogamos nos lo comunique inmediatamente
por esta misma via y proceda a su destruccion.

This e-mail is intended exclusively for the individual or entity to which it is addressed
and may contain confidential or legally privileged information, which may not be disclosed
under current legislation. Any form of disclosure, copying or distribution of this e-mail
is strictly prohibited, save with written authorisation from Iberdrola.
If you have received this message in error, please notify the sender immediately by e-mail
and delete all copies of the message.
=============================

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: