https://securityaffairs.com/194041/hacking/squidbleed-29-year-old-squid-bug-leaks-user-credentials.html
#securityaffairs #hacking
🤖 Squidbleed: a 29-year-old heap over-read in Squid proxy can leak cleartext HTTP requests containing credentials and session tokens. The bug traces to a 1997 FTP-parsing code change and affects the default configuration. Disclosed by Calif.io.
🔗 https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html
#Squidbleed #CyberSec #Proxy #Vulnerability
Squid Proxy Bug Exposes Cleartext HTTP Requests
A newly discovered bug, dubbed Squidbleed, has been found in the popular Squid web proxy, allowing attackers to intercept sensitive HTTP requests and steal valuable credentials. This 20-year-old vulnerability, traced back to a 1997 FTP-parsing change, still affects Squid's default configuration.
#SquidProxy #Cve202647729 #Squidbleed #HttpRequestExposure #ProxyVulnerability
Den Squid-Proxy zu fixen, damit er nicht mehr in http und ftp angegriffen werden kann...
Das ist ein wenig so, wie heute das Türschloss vom Stall einer Pony-Express-Station zu reparieren. 😜
Ja ok, jeder Bug ist es wert, gefunden und gefixt zu werden. 😉