Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Wednesday, August 19, 2009

Misconfigured Proxy Causes Security Alarm

Neohapsis and TweetyCoaster both reported this week that there was a newly discovered security leak in Blue Coat ProxySG systems. But in reality it turned out both these reports were a false alarm, caused by a mis-configured proxy. Apparently there was a policy installed on this particular proxy which allowed users to bypass authentication.

This is a good reminder, that our proxies are extremely powerful devices, and as admins, we need to verify the policy that we install on them on a regular basis to make sure the policies are still doing what we want and need them to do.

No comments: