daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3128-pentesting-squid.md (7677B)


      1 ---
      2 title: "3128/tcp - Pentesting Squid"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/3128-pentesting-squid.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3128-pentesting-squid.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3128/tcp - Pentesting Squid
     14 
     15 ## Basic Information
     16 
     17 **Squid** is a caching and forwarding HTTP proxy. Deployments use it for outbound access control, caching, reverse-proxy acceleration, and traffic filtering. It is an HTTP proxy rather than a SOCKS proxy, and TCP tunnelling is controlled through HTTP `CONNECT` and Squid ACLs. Port **3128** is conventional, but `http_port` is configurable.<sup>[[5]](#references)</sup>
     18 
     19 **Default port:** 3128
     20 
     21 ```text
     22 PORT     STATE  SERVICE      VERSION
     23 3128/tcp open   http-proxy   Squid http proxy 4.11
     24 ```
     25 
     26 ## Enumeration
     27 
     28 ### Web Proxy
     29 
     30 You can configure the discovered service as an HTTP proxy in your browser. If it requires proxy authentication, the client will prompt for a username and password.
     31 
     32 ```bash
     33 # Try to proxify curl
     34 curl --proxy http://10.10.11.131:3128 http://10.10.11.131
     35 ```
     36 
     37 ### Open-proxy / egress validation
     38 
     39 First verify whether it is really behaving as a forward proxy and whether outbound Internet access is allowed.
     40 
     41 ```bash
     42 # Fast open-proxy detection
     43 nmap -Pn -sV -p 3128 --script http-open-proxy <IP>
     44 
     45 # Confirm egress and learn the public IP used by the proxy
     46 curl -x http://<IP>:3128 https://ifconfig.me
     47 
     48 # If authentication is required, curl will usually show 407 Proxy Authentication Required
     49 curl -x http://<IP>:3128 http://example.com -v
     50 curl -x http://user:pass@<IP>:3128 http://example.com -v
     51 ```
     52 
     53 If the proxy is reachable but Internet egress is blocked, it may still be useful as an **internal pivot**.
     54 
     55 ### Nmap proxified
     56 
     57 You can also try to use the proxy to **scan internal TCP ports through Nmap**.\
     58 Configure proxychains to use the Squid proxy by adding the following line at the end of the `proxychains.conf` file: `http 10.10.10.10 3128`
     59 For proxies requiring authentication, append credentials to the configuration by including the username and password at the end: `http 10.10.10.10 3128 username passw0rd`.
     60 
     61 Then run Nmap with proxychains to scan from the proxy's perspective: `proxychains nmap -sT -Pn -n -p- localhost`. Proxychains only intercepts compatible TCP `connect()` calls, so avoid SYN/UDP scans and validate results manually because proxy errors can produce misleading port states.
     62 
     63 ### SPOSE Scanner
     64 
     65 Alternatively, the Squid Pivoting Open Port Scanner ([spose.py](https://github.com/aancw/spose)) can be used.<sup>[[1]](#references)</sup>
     66 
     67 ```bash
     68 python spose.py --proxy http://10.10.11.131:3128 --target 10.10.11.131
     69 ```
     70 
     71 ### Cache Manager enumeration
     72 
     73 Misconfigured Squid deployments sometimes expose the **Cache Manager**, which can leak version info, counters, ACL hints, peer configuration, and sometimes the full running configuration.<sup>[[2]](#references)</sup>
     74 
     75 On modern Squid versions this is usually exposed below `/squid-internal-mgr/`:
     76 
     77 ```bash
     78 # Enumerate available manager actions
     79 curl http://<IP>:3128/squid-internal-mgr/menu
     80 
     81 # Common high-value pages
     82 curl http://<IP>:3128/squid-internal-mgr/info
     83 curl http://<IP>:3128/squid-internal-mgr/counters
     84 curl http://<IP>:3128/squid-internal-mgr/active_requests
     85 
     86 # If cachemgr_passwd is configured and HTTP Basic auth is accepted
     87 curl -u any:PASSWORD http://<IP>:3128/squid-internal-mgr/config
     88 ```
     89 
     90 Older installations may also expose the historical `cache_object://` scheme through `squidclient`/`curl`; that scheme was removed during the Squid 6 series. If manager ACLs are weak, treat this as a sensitive administrative surface.<sup>[[2]](#references)</sup>
     91 
     92 ### ACL bypass / internal reachability tests
     93 
     94 A common win is finding that `http_access`, `Safe_ports`, `SSL_ports`, `to_localhost`, or `manager` ACLs were relaxed too much. Test both plain HTTP proxying and `CONNECT` tunneling.
     95 
     96 ```bash
     97 # Direct HTTP requests to RFC1918 / loopback targets through the proxy
     98 curl -x http://<IP>:3128 http://127.0.0.1:8080/ -v
     99 curl -x http://<IP>:3128 http://[::1]:8080/ -v
    100 curl -x http://<IP>:3128 http://169.254.169.254/latest/meta-data/ -v
    101 curl -x http://<IP>:3128 http://192.168.1.10:8000/ -v
    102 
    103 # Force a CONNECT tunnel and perform a TLS handshake with an internal TLS service
    104 openssl s_client -proxy <IP>:3128 -connect 127.0.0.1:443 -quiet
    105 openssl s_client -proxy <IP>:3128 -connect 10.10.10.20:8443 -quiet
    106 ```
    107 
    108 This is especially useful when Squid is installed on a bastion, printer server, CI runner, or appliance that can reach sensitive loopback-only services.
    109 
    110 ### Pivot & tooling configuration
    111 
    112 *Use Squid as a discovery pivot and a transparent upstream hop for CLI and browser tools.*<sup>[[4]](#references)</sup>
    113 
    114 - **Scan “from” the proxy:** run SPOSE through Squid to enumerate ports reachable from the proxy host/loopback. With [uv](https://github.com/astral-sh/uv) you can install deps and scan all TCP ports directly:
    115 
    116 ```bash
    117 uv add --script spose.py -r requirements.txt
    118 uv run spose.py --proxy http://SQUID_IP:3128 --target localhost --allports
    119 ```
    120 
    121 - **Proxychains for HTTP interaction:** append a strict HTTP entry at the bottom of `/etc/proxychains.conf`:
    122 
    123 ```ini
    124 [ProxyList]
    125 http    SQUID_IP   3128
    126 ```
    127 
    128 Then interact with internal listeners (e.g., a web UI bound to 127.0.0.1) transparently through Squid:
    129 
    130 ```bash
    131 proxychains curl http://127.0.0.1:9191 -v
    132 ```
    133 
    134 - **Chaining Burp/Browser → Squid:** configure Burp *Proxy → Settings → Network → Connections → Upstream proxy servers* to point to `http://SQUID_IP:3128`. Requests to internal hosts such as `http://127.0.0.1:9191` will traverse Browser → Burp → Squid → target, enabling full interception of services otherwise not reachable externally.
    135 
    136 For more generic tunnel and pivot techniques, see [Tunneling and Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md).
    137 
    138 ### Notes for proxy security reviews
    139 
    140 If you are **auditing Squid itself** (not just using it as a pivot), include these checks in scope:
    141 
    142 - **Open proxy exposure:** confirm whether unauthenticated users can relay traffic externally or into internal address space.
    143 - **Manager exposure:** `/squid-internal-mgr/menu` and related pages often disclose enough information to accelerate lateral movement.
    144 - **CONNECT restrictions:** weak `SSL_ports` / `Safe_ports` handling can turn Squid into a generic TCP tunnel to arbitrary ports.
    145 - **Parser/cache poisoning tests on outdated builds:** recent advisories and public research show that request smuggling, lenient chunked decoding, and cache-poisoning style bugs have affected Squid repeatedly. If you are testing an older or vendor-patched appliance, add controlled TE/CL desync and cache-variant poisoning checks to the test plan.<sup>[[3]](#references)</sup>
    146 
    147 ## References
    148 
    149 - [1] [SPOSE – Squid Pivoting Open Port Scanner](https://github.com/aancw/spose)
    150 - [2] [The Cache Manager - Squid Web Cache wiki](https://wiki.squid-cache.org/Features/CacheManager/Index)
    151 - [3] [Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days](https://megamansec.github.io/Squid-Security-Audit/)
    152 - [4] [HTB Bamboo walkthrough (Squid pivoting example)](https://0xdf.gitlab.io/2026/02/03/htb-bamboo.html)
    153 - [5] [Squid Web Cache wiki - configuring browsers and the default proxy port](https://wiki.squid-cache.org/SquidFaq/ConfiguringBrowsers)