Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: Port 3128 (tcp/udp) Attack Activity Port 3128 (tcp/udp) Attack Activity

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
[get complete service list]
Port Information
Protocol Service Name
tcp squid-http Proxy Server
tcp ReverseWWWTunnel [trojan] Reverse WWW Tunnel Backdoor
tcp RingZero [trojan] RingZero
Top IPs Scanning
User Comments
Submitted By Date
2012-08-25 16:07:47
Planet Lab uses this port as well
Ronnie 2010-05-25 20:52:09
This port is also used by WinProxy
Brian Porter 2004-02-11 00:46:11
MyDoom.C / Doomjuice;;;virus_k=101002
2004-02-06 22:18:45
The Win32.Mydoom computer-virus opens and listens to the TCP port 3127, (if this port is already in use, the worm tries the next one free from the range 3128- 3199). The backdoor appears to have two main functions: execution of remotely-supplied code, and port forwarding. Reference:
Johannes Ullrich 2002-10-12 08:57:51
scans on port 3128 usually look for badly configured proxy servers in order to use them to hide further intrusion attempts or to bypass company (or country wide) firewall rules restricting access to certain web sites. These scans usually come in sets that scan several ports frequently used by proxies (80,8080...) Port 3128 is usually used by 'squid', a very popular web proxy server that is also able to proxy other protocols (e.g. ftp). If you run a proxy server, make sure it only proxies request from the inside. The two most common configuration problems are to permit strangers to use the proxy server to attack other web sites, or even worse to allow strangers to use the proxy server to access web site ('intranet') sites on the inside.
Add a comment
CVE Links
CVE # Description