首页 时政热点 科技头条 智能AI 安全攻防 数码硬件 开发者生态 汽车 游戏 社会热点 开源推荐 医疗健康 归档 标签 关于

已有 29 年历史的 Squid 代理漏洞“Squidbleed”可能会泄露明文 HTTP 请求

摘要

A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the sa

the Squid proxy and heap
2026-06-22 1 阅读 约1分钟阅读 info@thehackernews.com (The Hacker News)
分享:
字号:
Squid Web 代理中的堆过度读取可能会将其他用户的明文 HTTP 请求(包括其携带的任何凭据或会话令牌)泄露给已允许通过同一代理发送流量的任何人。该错误可追溯到 1997 年 FTP 解析更改,并且仍然存在于 Squid 的默认配置中。 Calif.io 的研究人员在 6 月份披露了它,并将其命名为 Squidbleed(
这篇文章对您有帮助吗?

订阅66必读

每日精选科技资讯,直达你的邮箱