Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is HaProxy vulnerable to CVE 2007-6750 ?

    Scheduled Pinned Locked Moved pfSense Packages
    3 Posts 2 Posters 660 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • manjotscM
      manjotsc
      last edited by

      Does CVE-2007-6750 affect HaProxy, I run nmap with nmap -Pn --script vuln 66.1xx.xxx.13 ?

      PORT     STATE SERVICE
      53/tcp   open  domain
      80/tcp   open  http
      |_http-csrf: Couldn't find any CSRF vulnerabilities.
      |_http-dombased-xss: Couldn't find any DOM based XSS.
      |_http-passwd: ERROR: Script execution failed (use -d to debug)
      | http-slowloris-check: 
      |   VULNERABLE:
      |   Slowloris DOS attack
      |     State: LIKELY VULNERABLE
      |     IDs:  CVE:CVE-2007-6750
      |       Slowloris tries to keep many connections to the target web server open and hold
      |       them open as long as possible.  It accomplishes this by opening connections to
      |       the target web server and sending a partial request. By doing so, it starves
      |       the http server's resources causing Denial Of Service.
      |       
      |     Disclosure date: 2009-09-17
      |     References:
      |       http://ha.ckers.org/slowloris/
      |_      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750
      |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
      

      Vendor: HP
      Version: P01 Ver. 02.50
      Release Date: Wed Jul 17 2024
      Boot Method: UEFI
      24.11-RELEASE (amd64)
      FreeBSD 15.0-CURRENT
      CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
      Current: 3606 MHz, Max: 3400 MHz
      4 CPUs : 1 package(s) x 4 core(s)

      kiokomanK 1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8 @manjotsc
        last edited by

        @manjotsc
        haproxy isn't an apache http server, i don't see how this could be related to it
        haproxy just pass the traffic to the real server, if the real server is vulnerable it's not haproxy fault

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        manjotscM 1 Reply Last reply Reply Quote 0
        • manjotscM
          manjotsc @kiokoman
          last edited by

          @kiokoman Thanks, for cleariying

          Vendor: HP
          Version: P01 Ver. 02.50
          Release Date: Wed Jul 17 2024
          Boot Method: UEFI
          24.11-RELEASE (amd64)
          FreeBSD 15.0-CURRENT
          CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
          Current: 3606 MHz, Max: 3400 MHz
          4 CPUs : 1 package(s) x 4 core(s)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.