Mitigate the HTTPoxy vulnerability
Remove the Proxy header from requests to an application with a Rules Engine rule, so that HTTPoxy requests cannot redirect outgoing traffic.
You can protect an application against HTTPoxy from Azion Console with a Rules Engine rule that strips the Proxy header from every request. For the general procedure to add and order rules, refer to Create an application rule.
HTTPoxy targets web applications that run in Common Gateway Interface (CGI) or CGI-like environments. CGI handles user requests and passes data between client and server through environment variables. In these environments, a Proxy request header overwrites the HTTP_PROXY environment variable, which sets the outgoing proxy. An attacker can then send the internal requests of the application to an external proxy server and capture every piece of data they carry. For more information, refer to the HTTPoxy website or the CERT Coordination Center (CERT/CC) vulnerability database.
Prerequisites
- Access to Azion Console. To sign in, refer to How to access Azion Console.
- An application that receives the requests to protect.
Filter the Proxy header
The rule runs in the Request Phase and uses the Filter Request Header behavior, which requires no other Product on the application. A criterion of ${uri} with starts_with and / matches every request, so the rule covers the whole application.
To create the rule in Azion Console:
Access Azion Console > Applications, then select the application to protect.
Enter a name for the rule.
In the Criteria section, select ${uri} as the variable and starts_with as the operator, and enter / as the argument.
In the Behaviors section, select Filter Request Header and enter proxy as the argument.
The application removes the Proxy header from every request before it reaches your origin, so an HTTPoxy request cannot set the outgoing proxy.