THE DANGERS OF OPEN PROXY SERVERS
Open
proxy servers are those that do not require a password to logon or use.
Be
warned
- There are many dangers when using OPEN proxy servers.
Proxy
servers require high Internet resources and bandwidth in order to be able to provide
a public service. If someone is offering a free proxy service, you will want to
make sure that the person or company has nothing to gain and that you can trust
the connection. The
Proxy Connection offers over 700
virtual proxy servers spread across three separate dedicated networks.
Do not be DECEIVED! If someone is offering a free proxy service, there is a catch
somewhere. Considering the cost of bandwidth and machine maintenance, a free
proxy service is simply not feasible. If you are using a free proxy service or
one of the many open proxy lists, you could be trusting your data, email messages,
passwords or other personal information to a teenager that setup a proxy on the
local school network. While thinking that using such a service has made you more
secure, you have probably already become a victim.
Only proxy servers
that are offered by an established company with direct phone lines and technical
support should be used for security. An established business in the United States
has their company and much more to loose by not providing a safe computing environment.
If possible, always use a proxy server hosted by a company with some kind of security
background. There are security concerns that need to be addressed. If you sign
up for a proxy service that Joe started in his basement, you may miss out on a
full stealth environment and the full protection that you desire. An established
security company will have the experience and seasoned professionals to provide
you with a safe service.
How
Do I know If I Am Using An Open Proxy Server?
There are two common
ways to close a proxy server. When a proxy server is closed it will either force
you to connect -from- only one IP address or a range of IP addresses, or it will
require you to use a user name and password to connect and use it.
If you
do not need to type in a user name and password, it is virtually always an open
proxy server.
Some
Of the Dangers
There are many dangers that come along with using
open proxy servers. This is why many online Internet services and companies have
started checking or 'probing' your connection when you join their service. The
probing that is done is simple and harmless, it simply checks to see if your connection
has common proxy ports open. If the ports are found, the service will make sure
that it is a closed proxy system by attempting to make a connection to it. If
the connection is made, it will check to see if it requires a password to use
it. If the proxy is found to be open it will raise a red flag and sometimes deny
you from using or purchasing their services.
These service checks or probes
are harmless. They simply make sure that the user is not on an open proxy. If
the proxy is open, they have no way of making sure that you are who you claim
to be. There are far to many hackers using these open servers to commit credit
card fraud, attack other online users, hack into computers or any one of hundreds
of other illegal activities. If you are using an open proxy, someone can be
watching your every move! To date, there are COUNTLESS honeypots
and hackerpots out on the
net. While thinking that you have made yourself more secure, you have actually
opened yourself up for attack. When using an open proxy server, your PC is making
a direct connection to another computer. You also do not know who is in control
of this computer. Your passwords can be sniffed and your firewall tunneled. Your
privacy can also be invaded as this person reads your email, snags your ICQ, IRC,
AIM, MSN messages or any other unencrypted data that is sent through one of these
obvious honey or hackerpots.
Misconfigured
Proxy Servers
Most times when a proxy server is open it
is because it has been misconfigured on installation, or the person that configured
the server was simply not aware of the dangers in leaving it open. Other times
the server was not properly firewalled. In almost every case, you have no way
of knowing if the proxy server was open deliberately or if is was a misconfiguration.
There is no large banner that pops up and says "I left this proxy server
open for everyone in the world to connect to and use, come and eat up my bandwidth".
Most open proxy servers are simply 'scanned for' and 'found' misconfigured servers.
This accounts for them being on a list one day and gone the next. Often, when
the network bandwidth takes the hit of hundreds of computers using it at the same
time, the open proxy problem is found and quickly resolved.
Public
Proxy Lists
Beware!
Those that scan for open proxy servers and then add them to a public list, do
not care if you get in trouble while using them. If you are found using an unauthorized
server, it could be a class
II felony. The server that you are using could be located at some Government
agency or a company with a top level Government contract. Your real ISP information
will be available to them in their system logs and you could be hunted down and
prosecuted.
Honey
Pots
Honey
pots are open computers that are just waiting for someone to find and exploit.
After they are exploited, they are monitored for a time and then legal action
is often taken against those using these exploited systems.
Honey Pot machines are used by the Government all the time. It is a known fact
that many different Government branches setup honey pots to attract hackers, terrorists
and other offenders. A honey pot is a machine that is placed on the Internet wide
open for redirect or attack. Everything that is done on or through the system
is logged and traced. While the system is being used, complete information about
the perpetrator(s) is gathered. The 'hacker' becomes the 'hacked' and after a
period of time they have the hacker and his friends right where they want them.
If you happen across one of these open honey pot proxy servers, everything that
you do and every password that you use will be sniffed and logged. Included below
are only a few of the many articles that have been written about this topic.
By
Keith Johnson, WSJ Interactive Edition
December 19, 2000 6:01 AM PT
When
a group of suspected Pakistani hackers broke into a U.S.-based computer system
in June, they thought they had found a vulnerable network to use as an anonymous
launching pad to attack Web sites across India. But what they had done was walk
right into a trap known as a honeypot -- a specially equipped system deployed
by security professionals to lure hackers and track their every move. For a month,
every keystroke they made, every tool they used, every word of their online chat
sessions was recorded and studied. The honeypot administrators learned how the
hackers chose their targets, what level of expertise they had, what their favorite
kinds of attacks were, and how they went about trying to cover their tracks so
that they could nest on compromised systems. [read
the entire article :http://cert.uni-stuttgart.de...]
War
drivers beware, the next wireless network you tap might be part of an elaborate
sting. By Kevin Poulsen, Jul 29 2002 1:00AM
Hackers
searching for wireless access points in the nation's capital may soon war drive
right into a trap. Last month researchers at the government contractor Science
Applications International Corporation (SAIC) launched what might be the first
organized wireless honeypot, designed to tempt unwary Wi-Fi hackers and bandwidth
borrowers and gather data on their techniques and tools of choice.
[read
the entire article: http://online.securityfocus.com...]
For
a good article on honeypots:
The
Value of Honeypots, Part One: Definitions and Values of Honeypots by Lance Spitzner
with extensive help from Marty Roesch last updated October 10, 2001
[read
the entire article: http://online.securityfocus.com...]
Hacker
Pots
Hacking is at an all time high. The knowledge required to
break into a computer system a few years ago took some study and time. Today with
the vast library of information and hacking tools, anyone with limited knowledge
could get past a firewall or infect a computer with a trojan.
Hackers
of today, do not require much learning or effort at all. There are many 'over-night'
hackers that grow daily one step at a time, looking to learn the next method on
the list for finding their victims. Government agencies are not the only ones
that setup honey pots. All
a hacker needs to do is to put a proxy server up on his, or a victim's computer
and wait for a few hours for a scanner to find it. Within a day or two it is on
a public list and his packet sniffer is working overtime collecting users credit
card numbers, passwords and other personal information. While you use his open
proxy server, every web page that you visit, every message that you send and every
password that you type is logged. The Hacker Pots work the same way as the honeypots
shown above work, only are being run by hackers. You never know when using an
open proxy server if you are using a hackerpot or honeypot, but either way you
can be sure that someone is watching you somewhere when you are on an open proxy
server.
Reliability
And Privacy
If you are looking for reliability and privacy, open proxy
servers are not for you. When the proxy is open to everyone, it is being used
by many people at the same time. If the user to bandwidth or the user to CPU ratio
is not in sync, the system will drag down to a SLOW crawl. When you purchase a
proxy account, the proxy provider will need to keep up with their service and
add computers and bandwidth to accommodate their customers. When using an open
proxy, you will find that the server is up one day and gone the next. Most times
this is because the server was misconfigured and the high bandwidth usage attracted
the administrators who closed or fixed the proxy. In such cases the system logs
are almost always sent to the federal
computer crime squad. You also may spend hours searching for another
proxy in the list that is working, only to find that it is too slow to even load
a full text URL in under five minutes. Using an open Internet proxy can turn your
five minute Internet task into a three hour event, all for the sake of saving
a few dollars.
The
Proxy Connection Servers
All of the Proxy
Connection Servers are secure and located In-House. All of the top level domain
names are owned solely by The Proxy Connection and are completely legal to use
as one of our valued clients.
You never have to worry about what server or
network you are connected to. Here at the Proxy Connection we value your privacy
and commit ourselves to your having a safe and anonymous computing experience.