3128-pentesting-squid.md (7677B)
1 --- 2 title: "3128/tcp - Pentesting Squid" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/3128-pentesting-squid.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3128-pentesting-squid.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 3128/tcp - Pentesting Squid 14 15 ## Basic Information 16 17 **Squid** is a caching and forwarding HTTP proxy. Deployments use it for outbound access control, caching, reverse-proxy acceleration, and traffic filtering. It is an HTTP proxy rather than a SOCKS proxy, and TCP tunnelling is controlled through HTTP `CONNECT` and Squid ACLs. Port **3128** is conventional, but `http_port` is configurable.<sup>[[5]](#references)</sup> 18 19 **Default port:** 3128 20 21 ```text 22 PORT STATE SERVICE VERSION 23 3128/tcp open http-proxy Squid http proxy 4.11 24 ``` 25 26 ## Enumeration 27 28 ### Web Proxy 29 30 You can configure the discovered service as an HTTP proxy in your browser. If it requires proxy authentication, the client will prompt for a username and password. 31 32 ```bash 33 # Try to proxify curl 34 curl --proxy http://10.10.11.131:3128 http://10.10.11.131 35 ``` 36 37 ### Open-proxy / egress validation 38 39 First verify whether it is really behaving as a forward proxy and whether outbound Internet access is allowed. 40 41 ```bash 42 # Fast open-proxy detection 43 nmap -Pn -sV -p 3128 --script http-open-proxy <IP> 44 45 # Confirm egress and learn the public IP used by the proxy 46 curl -x http://<IP>:3128 https://ifconfig.me 47 48 # If authentication is required, curl will usually show 407 Proxy Authentication Required 49 curl -x http://<IP>:3128 http://example.com -v 50 curl -x http://user:pass@<IP>:3128 http://example.com -v 51 ``` 52 53 If the proxy is reachable but Internet egress is blocked, it may still be useful as an **internal pivot**. 54 55 ### Nmap proxified 56 57 You can also try to use the proxy to **scan internal TCP ports through Nmap**.\ 58 Configure proxychains to use the Squid proxy by adding the following line at the end of the `proxychains.conf` file: `http 10.10.10.10 3128` 59 For proxies requiring authentication, append credentials to the configuration by including the username and password at the end: `http 10.10.10.10 3128 username passw0rd`. 60 61 Then run Nmap with proxychains to scan from the proxy's perspective: `proxychains nmap -sT -Pn -n -p- localhost`. Proxychains only intercepts compatible TCP `connect()` calls, so avoid SYN/UDP scans and validate results manually because proxy errors can produce misleading port states. 62 63 ### SPOSE Scanner 64 65 Alternatively, the Squid Pivoting Open Port Scanner ([spose.py](https://github.com/aancw/spose)) can be used.<sup>[[1]](#references)</sup> 66 67 ```bash 68 python spose.py --proxy http://10.10.11.131:3128 --target 10.10.11.131 69 ``` 70 71 ### Cache Manager enumeration 72 73 Misconfigured Squid deployments sometimes expose the **Cache Manager**, which can leak version info, counters, ACL hints, peer configuration, and sometimes the full running configuration.<sup>[[2]](#references)</sup> 74 75 On modern Squid versions this is usually exposed below `/squid-internal-mgr/`: 76 77 ```bash 78 # Enumerate available manager actions 79 curl http://<IP>:3128/squid-internal-mgr/menu 80 81 # Common high-value pages 82 curl http://<IP>:3128/squid-internal-mgr/info 83 curl http://<IP>:3128/squid-internal-mgr/counters 84 curl http://<IP>:3128/squid-internal-mgr/active_requests 85 86 # If cachemgr_passwd is configured and HTTP Basic auth is accepted 87 curl -u any:PASSWORD http://<IP>:3128/squid-internal-mgr/config 88 ``` 89 90 Older installations may also expose the historical `cache_object://` scheme through `squidclient`/`curl`; that scheme was removed during the Squid 6 series. If manager ACLs are weak, treat this as a sensitive administrative surface.<sup>[[2]](#references)</sup> 91 92 ### ACL bypass / internal reachability tests 93 94 A common win is finding that `http_access`, `Safe_ports`, `SSL_ports`, `to_localhost`, or `manager` ACLs were relaxed too much. Test both plain HTTP proxying and `CONNECT` tunneling. 95 96 ```bash 97 # Direct HTTP requests to RFC1918 / loopback targets through the proxy 98 curl -x http://<IP>:3128 http://127.0.0.1:8080/ -v 99 curl -x http://<IP>:3128 http://[::1]:8080/ -v 100 curl -x http://<IP>:3128 http://169.254.169.254/latest/meta-data/ -v 101 curl -x http://<IP>:3128 http://192.168.1.10:8000/ -v 102 103 # Force a CONNECT tunnel and perform a TLS handshake with an internal TLS service 104 openssl s_client -proxy <IP>:3128 -connect 127.0.0.1:443 -quiet 105 openssl s_client -proxy <IP>:3128 -connect 10.10.10.20:8443 -quiet 106 ``` 107 108 This is especially useful when Squid is installed on a bastion, printer server, CI runner, or appliance that can reach sensitive loopback-only services. 109 110 ### Pivot & tooling configuration 111 112 *Use Squid as a discovery pivot and a transparent upstream hop for CLI and browser tools.*<sup>[[4]](#references)</sup> 113 114 - **Scan “from” the proxy:** run SPOSE through Squid to enumerate ports reachable from the proxy host/loopback. With [uv](https://github.com/astral-sh/uv) you can install deps and scan all TCP ports directly: 115 116 ```bash 117 uv add --script spose.py -r requirements.txt 118 uv run spose.py --proxy http://SQUID_IP:3128 --target localhost --allports 119 ``` 120 121 - **Proxychains for HTTP interaction:** append a strict HTTP entry at the bottom of `/etc/proxychains.conf`: 122 123 ```ini 124 [ProxyList] 125 http SQUID_IP 3128 126 ``` 127 128 Then interact with internal listeners (e.g., a web UI bound to 127.0.0.1) transparently through Squid: 129 130 ```bash 131 proxychains curl http://127.0.0.1:9191 -v 132 ``` 133 134 - **Chaining Burp/Browser → Squid:** configure Burp *Proxy → Settings → Network → Connections → Upstream proxy servers* to point to `http://SQUID_IP:3128`. Requests to internal hosts such as `http://127.0.0.1:9191` will traverse Browser → Burp → Squid → target, enabling full interception of services otherwise not reachable externally. 135 136 For more generic tunnel and pivot techniques, see [Tunneling and Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md). 137 138 ### Notes for proxy security reviews 139 140 If you are **auditing Squid itself** (not just using it as a pivot), include these checks in scope: 141 142 - **Open proxy exposure:** confirm whether unauthenticated users can relay traffic externally or into internal address space. 143 - **Manager exposure:** `/squid-internal-mgr/menu` and related pages often disclose enough information to accelerate lateral movement. 144 - **CONNECT restrictions:** weak `SSL_ports` / `Safe_ports` handling can turn Squid into a generic TCP tunnel to arbitrary ports. 145 - **Parser/cache poisoning tests on outdated builds:** recent advisories and public research show that request smuggling, lenient chunked decoding, and cache-poisoning style bugs have affected Squid repeatedly. If you are testing an older or vendor-patched appliance, add controlled TE/CL desync and cache-variant poisoning checks to the test plan.<sup>[[3]](#references)</sup> 146 147 ## References 148 149 - [1] [SPOSE – Squid Pivoting Open Port Scanner](https://github.com/aancw/spose) 150 - [2] [The Cache Manager - Squid Web Cache wiki](https://wiki.squid-cache.org/Features/CacheManager/Index) 151 - [3] [Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days](https://megamansec.github.io/Squid-Security-Audit/) 152 - [4] [HTB Bamboo walkthrough (Squid pivoting example)](https://0xdf.gitlab.io/2026/02/03/htb-bamboo.html) 153 - [5] [Squid Web Cache wiki - configuring browsers and the default proxy port](https://wiki.squid-cache.org/SquidFaq/ConfiguringBrowsers)