2.2.12 Ensure HTTP Proxy Server is not installed (Automated)
Profile
- Level 1 - Server
- Level 1 - Workstation
Description
Squid is a standard proxy server used in many distributions and environments.
Rationale
If there is no need for a proxy server, it is recommended that the squid proxy be deleted to reduce the potential attack surface.
Audit Procedure
Command Line
Run the following command to verify squid is not installed:
# dpkg-query -s squid &>/dev/null && echo "squid is installed"
Nothing should be returned.
Expected Result
No output (empty result).
Remediation
Command Line
Run the following command to remove squid:
# apt purge squid
References
- NIST SP 800-53 Rev. 5: CM-6, CM-7
Additional Information:
Several HTTP proxy servers exist. These and other services should be checked.
CIS Controls
- v8: 4.8 - Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- v7: 9.2 - Ensure Only Approved Ports, Protocols and Services Are Running