{"id":771,"date":"2017-02-24T12:49:24","date_gmt":"2017-02-24T12:49:24","guid":{"rendered":"http:\/\/reseller-hosting-themes.com\/wordpress\/?p=771"},"modified":"2017-03-13T14:57:55","modified_gmt":"2017-03-13T14:57:55","slug":"full-protection-httpoxy-cgi-vulnerability-all-servers","status":"publish","type":"post","link":"https:\/\/reseller-hosting-themes.com\/wordpress\/full-protection-httpoxy-cgi-vulnerability-all-servers\/","title":{"rendered":"Full protection from httpoxy CGI vulnerability on all servers"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" class=\"alignright wp-image-1033 size-medium\" src=\"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-content\/uploads\/2016\/11\/httpoxy-protection-servers-300x225.png\" alt=\"httpoxy protection servers\" width=\"300\" height=\"225\" srcset=\"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-content\/uploads\/2016\/11\/httpoxy-protection-servers-300x225.png 300w, https:\/\/reseller-hosting-themes.com\/wordpress\/wp-content\/uploads\/2016\/11\/httpoxy-protection-servers.png 640w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>One of the main causes for discomfort among Internet users lately is a recently re-discovered server-side application vulnerability &#8211; httpoxy.<\/p>\n<p>It affects applications whose code is executed in CGI or other CGI-like environments.<\/p>\n<p>One of the measures taken\u00a0in order to address this vulnerability was to enable automatic website and app protection for managed solutions on the\u00a0web hosting platform.<\/p>\n<h2>How does the &#8216;httpoxy&#8217; vulnerability work?<\/h2>\n<p>The reason why the &#8216;httpoxy&#8217; vulnerability presents such a threat is the fact that it provides &#8216;a green corridor&#8217; for individuals with malicious intentions &#8211; thus allowing them to exploit the communication between a web application and other external applications via API.<\/p>\n<p>Some of the unwanted consequences of a vulnerable web application making an outgoing HTTP connection are:<\/p>\n<p>\u2022 the outgoing HTTP requests could be proxied<br \/>\n\u2022 the server can be\u00a0configured to send private information to a particular address and port<br \/>\n\u2022 it forces\u00a0the application to use a malicious proxy<br \/>\n\u2022 it exhausts the server resources<\/p>\n<p>In case a hacker makes a request that includes a \u2018Proxy\u2019 request header &#8211; an outgoing connection can be\u00a0exploited.<\/p>\n<p>The aforementioned header is subsequently turned by the CGI into an environment variable called HTTP_PROXY.\u00a0In turn it configures an outgoing proxy.<\/p>\n<p>Afterwards, the web application makes a request to a destination selected by the hacker rather than to the particular API.<\/p>\n<h2>Protection measures against &#8216;httpoxy&#8217; (Managed Services):<\/h2>\n<p>We patched all of the web hosting services that are under our control the instant we were informed about the &#8216;httpoxy&#8217; vulnerability.<\/p>\n<p>Among these web hosting services are:<br \/>\n\u2022 All <a href=\"https:\/\/www.resellerspanel.com\/cloud-web-hosting\/\">web hosting services<\/a><br \/>\n\u2022 All <a href=\"https:\/\/www.resellerspanel.com\/semi-dedicated-hosting\/\">semi-dedicated servers<\/a><br \/>\n\u2022 Hepsia Control Panel-managed OpenVZ Virtual Private Servers<br \/>\n\u2022 Managed <a href=\"https:\/\/www.resellerspanel.com\/virtual-private-servers\/openvz\/\">OpenVZ Virtual Private Servers<\/a><br \/>\n\u2022 Hepsia Control Panel-managed dedicated servers<br \/>\n\u2022 Managed <a href=\"https:\/\/www.resellerspanel.com\/dedicated-servers\/\">dedicated servers<\/a><\/p>\n<h2>Protection measures against &#8216;httpoxy&#8217; (Unmanaged Services):<\/h2>\n<p>You will have to take immediate measures to protect your applications from the &#8216;httpoxy&#8217; vulnerability &#8211; provided you are using a non-managed OpenVZ server, a KVM VPS or a dedicated server, or\/and do not use the <a href=\"https:\/\/www.resellerspanel.com\/cloud-web-hosting\/control-panel-demo\/\">Hepsia Control Panel<\/a>.<\/p>\n<p>In the following cases your applications are immune to the &#8216;httpoxy&#8217; vulnerability:<\/p>\n<p>\u2022 since &#8216;httpoxy&#8217; only affects unencrypted requests, your applications would be totally safe if they are making API requests over an encrypted (SSL\/TLS\/HTTPS) connection<br \/>\n\u2022 if you use one of the many faster and better code environment alternatives of CGI that were\u00a0introduced over the last few years<\/p>\n<p>Another solution that would keep you safe in case you are using CGI with no encrypted connection is to block the \u2018Proxy\u2019 header.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn more about httpoxy and how to protect your accounts and servers from this PHP vulnerability. Users with managed services are already secured.<\/p>\n","protected":false},"author":1,"featured_media":1033,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"_links":{"self":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts\/771"}],"collection":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/comments?post=771"}],"version-history":[{"count":10,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts\/771\/revisions"}],"predecessor-version":[{"id":1236,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/posts\/771\/revisions\/1236"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/media\/1033"}],"wp:attachment":[{"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/media?parent=771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/categories?post=771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/reseller-hosting-themes.com\/wordpress\/wp-json\/wp\/v2\/tags?post=771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}