500 Proxy Error

1,448 views
Skip to first unread message

Snoopy21

unread,
Sep 10, 2021, 10:30:59 AM9/10/21
to RCDevs Security Solutions - Technical
two of our servers have suddenly generated this error, we are using WAproxy and ssl certificates are OK

Proxy ErrorThe proxy server could not handle the request

Reason: Error during SSL Handshake with remote server

Snoopy21

unread,
Sep 10, 2021, 10:57:51 AM9/10/21
to RCDevs Security Solutions - Technical

in waproxy.log we see this...

[2021-09-10 15:53:51] [185.30.229.67:62534] AH01097: pass request body failed to 192.168.0.5:443 (192.168.0.5) from 185.30.229.67 ()
[2021-09-10 15:55:32] [192.168.165.14:58095] AH01084: pass request body failed to 192.168.0.5:443 (192.168.0.5)
[2021-09-10 15:55:32] [192.168.165.14:58095] AH00898: Error during SSL Handshake with remote server returned by /
[2021-09-10 15:55:32] [192.168.165.14:58095] AH01097: pass request body failed to 192.168.0.5:443 (192.168.0.5) from 192.168.165.14 ()
[2021-09-10 15:55:42] [192.168.165.14:58121] AH01084: pass request body failed to 192.168.0.5:443 (192.168.0.5)
[2021-09-10 15:55:42] [192.168.165.14:58121] AH00898: Error during SSL Handshake with remote server returned by /
[2021-09-10 15:55:42] [192.168.165.14:58121] AH01097: pass request body failed to 192.168.0.5:443 (192.168.0.5) from 192.168.165.14 ()
[2021-09-10 15:55:43] [192.168.165.14:58126] AH01084: pass request body failed to 192.168.0.5:443 (192.168.0.5)
[2021-09-10 15:55:43] [192.168.165.14:58126] AH00898: Error during SSL Handshake with remote server returned by /
[2021-09-10 15:55:43] [192.168.165.14:58126] AH01097: pass request body failed to 192.168.0.5:443 (192.168.0.5) from 192.168.165.14 ()

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 5:03:50 AM9/13/21
to RCDevs Security Solutions - Technical
Hello,

Can you provide the version of your waproxy and webadm:
cat /opt/waproxy/VERSION
cat /opt/webadm/VERSION

Can you also provide the following file from webadm server:
/opt/webadm/conf/webadm.env

Can you also provide the following file from waproxy server:
/opt/waproxy/conf/waproxy.env

Also, did you updated recently webadm?


Best regards

Snoopy21

unread,
Sep 13, 2021, 5:18:05 AM9/13/21
to RCDevs Security Solutions - Technical
[root@rcvm8 ~]# cat /opt/webadm/VERSION
RCDevs WebADM Server v2.0.19 for Linux 64bit
Built May 12 2021

Including component versions:
- curl 7.76.1
- gmp 6.2.1
- apache 2.4.46
- libmcrypt 2.5.8
- libxml 2.9.10
- libpng 1.6.37
- openldap 2.5.4
- openssl 1.1.1k
- php 7.4.18
- redis 6.2.3
- unixodbc 2.3.9
- zlib 1.2.11
- libxmlrpc 0.54.2
- libqrencode 4.1.1
- maxmind 1.5.2
- libaudit 2.4.5
- libnghttp2 1.41.0
- libhiredis 1.0.0
[root@rcvm8 ~]# 


[root@sec ~]# cat /opt/waproxy/VERSION
RCDevs WebADM Publishing Proxy v1.1.11 for Linux 64bit
Built March 29 2021

Including component versions:
- apache 2.4.46
- openssl 1.1.1k
- zlib 1.2.11
- curl 7.75.0[root@sec ~]# 

Snoopy21

unread,
Sep 13, 2021, 5:20:41 AM9/13/21
to RCDevs Security Solutions - Technical

the file /opt/webadm/conf/webadm.env is not there

On Monday, 13 September 2021 at 10:03:50 UTC+1 Benoît Jager (RCDevs) wrote:
Screenshot 2021-09-13 at 10.19.41.png

Snoopy21

unread,
Sep 13, 2021, 5:22:36 AM9/13/21
to RCDevs Security Solutions - Technical
The file /opt/waproxy/conf/waproxy.env is not there

On Monday, 13 September 2021 at 10:03:50 UTC+1 Benoît Jager (RCDevs) wrote:
Screenshot 2021-09-13 at 10.21.58.png

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 5:30:10 AM9/13/21
to RCDevs Security Solutions - Technical
If you can install nmap on the server, can you provide with the result of these commands from your waproxy server:
nmap -sV --script ssl-enum-ciphers -p 443 192.168.0.5
nmap -sV --script ssl-enum-ciphers -p 443 127.0.0.1

This will list what TLS version your webadm and waproxy server can provide.

Snoopy21

unread,
Sep 13, 2021, 5:34:30 AM9/13/21
to RCDevs Security Solutions - Technical

PORT    STATE SERVICE  VERSION
443/tcp open  ssl/http Apache httpd
| ssl-enum-ciphers: 
|   SSLv3: No supported ciphers found
|   TLSv1.2: 
|     ciphers: 
|       TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
|       TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 - strong
|       TLS_DHE_RSA_WITH_AES_128_CCM - strong
|       TLS_DHE_RSA_WITH_AES_128_CCM_8 - strong
|       TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 - strong
|       TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
|       TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 - strong
|       TLS_DHE_RSA_WITH_AES_256_CCM - strong
|       TLS_DHE_RSA_WITH_AES_256_CCM_8 - strong
|       TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 - strong
|       TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 - strong
|       TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 - strong
|       TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - strong
|       TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 - strong
|       TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA - strong
|       TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 - strong
|       TLS_DHE_RSA_WITH_SEED_CBC_SHA - strong
|       TLS_RSA_WITH_AES_128_CBC_SHA - strong
|       TLS_RSA_WITH_AES_128_CBC_SHA256 - strong
|       TLS_RSA_WITH_AES_128_CCM - strong
|       TLS_RSA_WITH_AES_128_CCM_8 - strong
|       TLS_RSA_WITH_AES_128_GCM_SHA256 - strong
|       TLS_RSA_WITH_AES_256_CBC_SHA - strong
|       TLS_RSA_WITH_AES_256_CBC_SHA256 - strong
|       TLS_RSA_WITH_AES_256_CCM - strong
|       TLS_RSA_WITH_AES_256_CCM_8 - strong
|       TLS_RSA_WITH_AES_256_GCM_SHA384 - strong
|       TLS_RSA_WITH_ARIA_128_GCM_SHA256 - strong
|       TLS_RSA_WITH_ARIA_256_GCM_SHA384 - strong
|       TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong
|       TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 - strong
|       TLS_RSA_WITH_CAMELLIA_256_CBC_SHA - strong
|       TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 - strong
|       TLS_RSA_WITH_SEED_CBC_SHA - strong
|     compressors: 
|       NULL

Snoopy21

unread,
Sep 13, 2021, 5:39:48 AM9/13/21
to RCDevs Security Solutions - Technical
Nmap scan report for localhost (127.0.0.1)
Host is up (0.000068s latency).
|_  least strength: strong

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 5:39:53 AM9/13/21
to RCDevs Security Solutions - Technical
Can you provide the result of the 2 commands (for 192.168.0.5 and localhost)?
nmap -sV --script ssl-enum-ciphers -p 443 192.168.0.5
and
nmap -sV --script ssl-enum-ciphers -p 443 127.0.0.1

Snoopy21

unread,
Sep 13, 2021, 5:42:06 AM9/13/21
to RCDevs Security Solutions - Technical
sorry first one is nmap -sV --script ssl-enum-ciphers -p 443 192.168.0.5
second post is nmap -sV --script ssl-enum-ciphers -p 443 127.0.0.1

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 5:49:52 AM9/13/21
to RCDevs Security Solutions - Technical
From the waproxy server, what is the result of this command:

can you provide the configuration of waproxy:
/opt/waproxy/conf/waproxy.conf
Message has been deleted

Snoopy21

unread,
Sep 13, 2021, 6:05:39 AM9/13/21
to RCDevs Security Solutions - Technical
[root@sec ~]# curl -kv https://192.168.0.5
* About to connect() to 192.168.0.5 port 443 (#0)
*   Trying 192.168.0.5...
* Connected to 192.168.0.5 (192.168.0.5) port 443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* skipping SSL peer certificate verification
* SSL connection using TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
* Server certificate:
* subject: CN=our.fqdn.com
* start date: Jun 03 11:49:27 2021 GMT
* expire date: Sep 01 11:49:27 2021 GMT
* common name: our.fqdn.com
* issuer: CN=R3,O=Let's Encrypt,C=US
> GET / HTTP/1.1
> User-Agent: curl/7.29.0
> Host: 192.168.0.5
> Accept: */*
< HTTP/1.1 302 Found
< Date: Mon, 13 Sep 2021 09:55:05 GMT
< Server: Apache
< Strict-Transport-Security: max-age=63072000; includeSubDomains
< Content-Security-Policy: child-src 'self' data: blob:
< Cache-Control: private, must-revalidate
< X-Robots-Tag: noindex, nofollow
< location: admin/index.php
< Content-Length: 0
< Content-Type: text/html; charset=utf-8
* Connection #0 to host 192
waproxy.conf

Snoopy21

unread,
Sep 13, 2021, 7:12:32 AM9/13/21
to RCDevs Security Solutions - Technical

Hi any idea's ?
Message has been deleted

Snoopy21

unread,
Sep 13, 2021, 7:23:05 AM9/13/21
to RCDevs Security Solutions - Technical

Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .

Nmap done: 1 IP address (1 host up) scanned in 12.46 seconds

* Connection #0 to host 192.168.0.5 left intact

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 7:27:22 AM9/13/21
to RCDevs Security Solutions - Technical
Can you provide the /opt/webadm/logs/webadm.log file from 192.168.0.5 machine? I can provide you with a Nextcloud link so you can upload it. Let me know.

Rob

unread,
Sep 13, 2021, 7:35:28 AM9/13/21
to rcdevs-t...@googlegroups.com
Yes sure 

Sent from my iPhone


On 13 Sep 2021, at 12:27, 'Benoît Jager ' via RCDevs Security Solutions - Technical <rcdevs-t...@googlegroups.com> wrote:


--
You received this message because you are subscribed to a topic in the Google Groups "RCDevs Security Solutions - Technical" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/rcdevs-technical/3-0mJzeK-6M/unsubscribe.
To unsubscribe from this group and all its topics, send an email to rcdevs-technic...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/rcdevs-technical/616a5a72-188c-49a5-adf7-c622e2977b0dn%40googlegroups.com.

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 7:37:52 AM9/13/21
to RCDevs Security Solutions - Technical

Rob

unread,
Sep 13, 2021, 7:45:46 AM9/13/21
to rcdevs-t...@googlegroups.com

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 7:50:13 AM9/13/21
to RCDevs Security Solutions - Technical
Can you upload all webadm.log files (e.g. with .1 .2.gz)? I have only logs from today in what you uploaded.

Rob

unread,
Sep 13, 2021, 7:51:23 AM9/13/21
to rcdevs-t...@googlegroups.com
There are only two I will upload the other





Rob

unread,
Sep 13, 2021, 8:38:50 AM9/13/21
to rcdevs-t...@googlegroups.com
I have done that.


Thank you


Snoopy21

unread,
Sep 13, 2021, 10:55:30 AM9/13/21
to RCDevs Security Solutions - Technical

I have done that again as I didn't hear back there was only one other log file in .gz format I uploaded a few hours ago and just again now as maybe you didn't get it first time

Benoît Jager (RCDevs)

unread,
Sep 13, 2021, 11:00:45 AM9/13/21
to RCDevs Security Solutions - Technical
Hello,
From the logs, I see no error on webadm side. Do you still encounter this issue?
If possible, could you run this tcpdump command on your webadm server, and do a request to your waproxy IP to see if something is going to webadm:
tcpdump -w waproxy.pcap -i any port 443 and host <REPLACE HERE WITH IP OF YOUR WAPROXY>

and upload the resulting waproxy.pcap file?


Best regards

Snoopy21

unread,
Sep 13, 2021, 11:10:06 AM9/13/21
to RCDevs Security Solutions - Technical
i have uploaded the file

Rob

unread,
Sep 14, 2021, 5:13:07 AM9/14/21
to rcdevs-t...@googlegroups.com
Hi,

I did this and uploaded…

This has happened on two servers …

I really don’t understand why…


Benoît Jager (RCDevs)

unread,
Sep 14, 2021, 5:17:08 AM9/14/21
to RCDevs Security Solutions - Technical
Hello,

can you restart the waproxy and webadm servers?

when you say this has happened on two servers, do you mean two waproxy servers?

Best regards

Rob

unread,
Sep 14, 2021, 5:18:37 AM9/14/21
to rcdevs-t...@googlegroups.com
I will however I did restart both before I mean its two separate installations…



Rob

unread,
Sep 14, 2021, 5:47:38 AM9/14/21
to rcdevs-t...@googlegroups.com
We are just buying a licence for the server with the +20% SLA as the system is now mission critical I will have a licence shortly.

We had always meant to but this but continued without for no very good reason.

Hopefully we will get our licence soon and you can hop on and take a deeper look

Thanks

Rob



Rob

unread,
Sep 14, 2021, 5:57:02 AM9/14/21
to rcdevs-t...@googlegroups.com
I have restarted the rcdevs 2fa server and waproxy

no difference



Benoît Jager (RCDevs)

unread,
Sep 14, 2021, 6:04:23 AM9/14/21
to RCDevs Security Solutions - Technical
Ok, can you redo the whole setup process for waproxy using
/opt/waproxy/bin/setup

this will ask you to validate the certificate issuing from webadm web interface

Rob

unread,
Sep 14, 2021, 6:41:24 AM9/14/21
to rcdevs-t...@googlegroups.com
Ok

Sent from my iPhone


On 14 Sep 2021, at 11:04, 'Benoît Jager ' via RCDevs Security Solutions - Technical <rcdevs-t...@googlegroups.com> wrote:

Ok, can you redo the whole setup process for waproxy using

Rob

unread,
Sep 14, 2021, 6:42:15 AM9/14/21
to rcdevs-t...@googlegroups.com
This won’t delete our users will it ?

Sent from my iPhone


On 14 Sep 2021, at 11:04, 'Benoît Jager ' via RCDevs Security Solutions - Technical <rcdevs-t...@googlegroups.com> wrote:

Ok, can you redo the whole setup process for waproxy using

Benoît Jager (RCDevs)

unread,
Sep 14, 2021, 7:07:55 AM9/14/21
to RCDevs Security Solutions - Technical
No, this will regenerate only certificates on waproxy side.

Rob

unread,
Sep 14, 2021, 8:36:11 AM9/14/21
to rcdevs-t...@googlegroups.com
it says all good and even got a new lets encrypt cert.

I accepted the certificate on the webadm interface still nothing



Reply all
Reply to author
Forward
0 new messages