{"id":9183,"date":"2016-07-19T09:36:35","date_gmt":"2016-07-19T15:36:35","guid":{"rendered":"https:\/\/www.siteground.com\/blog\/?p=9183"},"modified":"2025-09-18T14:49:05","modified_gmt":"2025-09-18T14:49:05","slug":"httpoxy-vulnerability","status":"publish","type":"post","link":"https:\/\/www.siteground.com\/blog\/httpoxy-vulnerability\/","title":{"rendered":"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off"},"content":{"rendered":"\n<p>A dangerous easy-to-exploit vulnerability called <a href=\"https:\/\/httpoxy.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">httpoxy<\/a> discovered 15 years ago, reappeared again yesterday, leaving server-side website software potentially open to attackers. This security hole impacts a large number of PHP and CGI web-apps. This means that anything that runs on PHP, Apache, Go, HHVM, Python can be vulnerable. The exploit allows man-in-the-middle attacks that could compromise web servers and potentially access sensitive data or seize control of the code. Thanks to our unique in-house developed systems and some precautions taken ahead of time by our DevOps team, SiteGround customers are unaffected by the return of the vulnerability.<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">How does the exploit work?<\/h2>\n\n\n\n<p>The abuser crafts a specific Proxy HTTP header in a request to the application to set a common environment variable called HTTP_PROXY on the application&#8217;s server. The app then, due to a naming conflict uses the proxy server defined by that variable for any of its outgoing HTTP connections. In such manner if the attacker has pointed the HTTP_PROXY at a malicious server, you can intercept the web app&#8217;s connections to other systems and, depending on how the code is designed, potentially gain remote code execution. The best immediate mitigation is to block PROXY request headers as early as possible, and before they hit your application.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How we avoided being affected by the vulnerability now?<\/h2>\n\n\n\n<p>We have our own unique in-house PHP and CGI setup that we developed in 2007 and continue to maintain and improve until today. Way back then when our DevOps team started to develop this setup, they were aware of the potential fault in using the PROXY header. That\u2019s why, as a precaution, they decided to exclude the PROXY header from our list of allowed environment parameters. This means that we don\u2019t even need to unset the HTTP_PROXY header as the security advisors suggest in this case, we simply do not allow it to be included in any HTTP requests.<\/p>\n\n\n\n<p>Thanks to our knowledgeable security and systems design team, we were able to predict the possibility of a reappearance of this vulnerability and we proactively designed our systems in a way to protect our clients.<\/p>\n\n\n<p>[subscribe_cta]<\/p>\n","protected":false},"excerpt":{"rendered":"A dangerous easy-to-exploit vulnerability called httpoxy discovered 15 years ago, reappeared again yesterday, leaving server-side website software potentially open to attackers. This security hole impacts a large number of PHP and CGI web-apps. This means that anything that runs on PHP, Apache, Go, HHVM, Python can be vulnerable. The exploit allows man-in-the-middle attacks that could&hellip;","protected":false},"author":57,"featured_media":9189,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2098,2018,12],"tags":[],"class_list":["post-9183","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hosting-insights","category-product-updates","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.2 (Yoast SEO v24.2) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off : SiteGround Blog<\/title>\n<meta name=\"description\" content=\"SiteGround designs its systems in such a way that even in the case of such vulnerabilities, our clients are safe and fully protected!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off\" \/>\n<meta property=\"og:description\" content=\"A dangerous easy-to-exploit vulnerability called httpoxy discovered 15 years ago, reappeared again yesterday, leaving server-side website software\" \/>\n<meta property=\"og:url\" content=\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"SiteGround\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/siteground\" \/>\n<meta property=\"article:published_time\" content=\"2016-07-19T15:36:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-18T14:49:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg\" \/>\n<meta name=\"author\" content=\"Daniel Kanchev\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@siteground\" \/>\n<meta name=\"twitter:site\" content=\"@siteground\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Kanchev\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\"},\"author\":{\"name\":\"Daniel Kanchev\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572\"},\"headline\":\"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off\",\"datePublished\":\"2016-07-19T15:36:35+00:00\",\"dateModified\":\"2025-09-18T14:49:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\"},\"wordCount\":366,\"commentCount\":26,\"publisher\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg\",\"articleSection\":[\"Hosting Insights\",\"Product Updates\",\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\",\"url\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\",\"name\":\"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off : SiteGround Blog\",\"isPartOf\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg\",\"datePublished\":\"2016-07-19T15:36:35+00:00\",\"dateModified\":\"2025-09-18T14:49:05+00:00\",\"description\":\"SiteGround designs its systems in such a way that even in the case of such vulnerabilities, our clients are safe and fully protected!\",\"breadcrumb\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage\",\"url\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg\",\"contentUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg\",\"width\":660,\"height\":300},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/newblog.siteground.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#website\",\"url\":\"https:\/\/newblog.siteground.com\/en\/\",\"name\":\"SiteGround Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/newblog.siteground.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#organization\",\"name\":\"SiteGround Blog\",\"url\":\"https:\/\/newblog.siteground.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg\",\"contentUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg\",\"width\":1200,\"height\":400,\"caption\":\"SiteGround Blog\"},\"image\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/siteground\",\"https:\/\/x.com\/siteground\",\"https:\/\/www.instagram.com\/siteground\/\",\"https:\/\/www.youtube.com\/@siteground\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572\",\"name\":\"Daniel Kanchev\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g\",\"caption\":\"Daniel Kanchev\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/daniel-kanchev-29716455\/\"],\"url\":\"https:\/\/newblog.siteground.com\/en\/author\/daniel\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off : SiteGround Blog","description":"SiteGround designs its systems in such a way that even in the case of such vulnerabilities, our clients are safe and fully protected!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off","og_description":"A dangerous easy-to-exploit vulnerability called httpoxy discovered 15 years ago, reappeared again yesterday, leaving server-side website software","og_url":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/","og_site_name":"SiteGround","article_publisher":"https:\/\/www.facebook.com\/siteground","article_published_time":"2016-07-19T15:36:35+00:00","article_modified_time":"2025-09-18T14:49:05+00:00","og_image":[{"url":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg","type":"","width":"","height":""}],"author":"Daniel Kanchev","twitter_card":"summary_large_image","twitter_creator":"@siteground","twitter_site":"@siteground","twitter_misc":{"Written by":"Daniel Kanchev","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#article","isPartOf":{"@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/"},"author":{"name":"Daniel Kanchev","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572"},"headline":"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off","datePublished":"2016-07-19T15:36:35+00:00","dateModified":"2025-09-18T14:49:05+00:00","mainEntityOfPage":{"@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/"},"wordCount":366,"commentCount":26,"publisher":{"@id":"https:\/\/newblog.siteground.com\/en\/#organization"},"image":{"@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg","articleSection":["Hosting Insights","Product Updates","Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/","url":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/","name":"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off : SiteGround Blog","isPartOf":{"@id":"https:\/\/newblog.siteground.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg","datePublished":"2016-07-19T15:36:35+00:00","dateModified":"2025-09-18T14:49:05+00:00","description":"SiteGround designs its systems in such a way that even in the case of such vulnerabilities, our clients are safe and fully protected!","breadcrumb":{"@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#primaryimage","url":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg","contentUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2016\/07\/httpoxy-vulnerability.jpg","width":660,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/newblog.siteground.com\/en\/httpoxy-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/newblog.siteground.com\/en\/"},{"@type":"ListItem","position":2,"name":"Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off"}]},{"@type":"WebSite","@id":"https:\/\/newblog.siteground.com\/en\/#website","url":"https:\/\/newblog.siteground.com\/en\/","name":"SiteGround Blog","description":"","publisher":{"@id":"https:\/\/newblog.siteground.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/newblog.siteground.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/newblog.siteground.com\/en\/#organization","name":"SiteGround Blog","url":"https:\/\/newblog.siteground.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg","contentUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg","width":1200,"height":400,"caption":"SiteGround Blog"},"image":{"@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/siteground","https:\/\/x.com\/siteground","https:\/\/www.instagram.com\/siteground\/","https:\/\/www.youtube.com\/@siteground"]},{"@type":"Person","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572","name":"Daniel Kanchev","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g","caption":"Daniel Kanchev"},"sameAs":["https:\/\/www.linkedin.com\/in\/daniel-kanchev-29716455\/"],"url":"https:\/\/newblog.siteground.com\/en\/author\/daniel\/"}]}},"_links":{"self":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts\/9183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/comments?post=9183"}],"version-history":[{"count":3,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts\/9183\/revisions"}],"predecessor-version":[{"id":17872,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts\/9183\/revisions\/17872"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/media\/9189"}],"wp:attachment":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/media?parent=9183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/categories?post=9183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/tags?post=9183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}