Falco informational stable other

Program run with disallowed http proxy env

Detect curl or wget usage with HTTP_PROXY environment variable. Attackers can manipulate the HTTP_PROXY variable's value to redirect application's internal HTTP requests. This could expose sensitive information like authentication keys and private data.

View Source

Detection Logic

spawned_process and http_proxy_procs and proc.env icontains HTTP_PROXY and not allowed_ssh_proxy_env

Field Validations

Loading…

Comments (0)

Loading comments...