cognitive cybersecurity intelligence

News and Analysis

Search

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests


A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.

The bug traces to a 1997 FTP-parsing change and is still live in Squid’s default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed (

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Cybersecurity Outsourcing. Beyond Cost

Cybersecurity Outsourcing. Beyond Cost

Why Security Outsourcing Is a Strategic, Not Just Operational, Decision Cybersecurity Outsourcing. Beyond Cost: Why Security Outsourcing Is a Strategic, Not Just Operational, Decision Outsourcing