安全攻防
evening
已有 29 年历史的 Squid 代理漏洞“Squidbleed”可能会泄露明文 HTTP 请求
摘要
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the sa
the
Squid
proxy
and
heap
2026-06-22
1 阅读
约1分钟阅读
info@thehackernews.com (The Hacker News)
字号:
Squid Web 代理中的堆过度读取可能会将其他用户的明文 HTTP 请求(包括其携带的任何凭据或会话令牌)泄露给已允许通过同一代理发送流量的任何人。该错误可追溯到 1997 年 FTP 解析更改,并且仍然存在于 Squid 的默认配置中。 Calif.io 的研究人员在 6 月份披露了它,并将其命名为 Squidbleed(
这篇文章对您有帮助吗?
订阅66必读
每日精选科技资讯,直达你的邮箱