Port 3128: Squid HTTP proxy
Squid's suggested configuration notes that Squid normally listens to port 3128 (http_port). Organizations run Squid as a forward or caching web proxy for client traffic. IANA lists 3128 under ndl-aas (Active API Server Port), which differs from this common use.
Port Details
Security Exposure
A proxy that accepts requests from anyone becomes an open proxy. Shadowserver notes that HTTP proxies are also used for attacks and other abuse, and its open proxy scans typically report ports such as 3128, 1080 and 8080. Squid's FAQ warns that untrusted users will find and abuse an open proxy, for semi-anonymous browsing or illegal transactions, and that public lists of open HTTP proxies exist.
Hardening
- +Keep the default http_access deny all rule last and allow only defined local networks.
- +Bind http_port to an internal address so Squid is not visible on external interfaces.
- +Require proxy authentication where users connect from networks that are not fully trusted.
- +Retest the access control rules after configuration changes to confirm the proxy is not open.
Monitoring
Review Squid access logs for requests from client addresses outside the allowed networks and for CONNECT requests to unusual ports. Shadowserver reports for an organization's address space flag open proxies found by external scans.
Squid proxy Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-33526 | Squid vulnerable to Denial of Service in ICP Request handling | squid-cache | 9.2 | 12.8% | 2026-03-26 |
Tools for Auditing and Monitoring Squid proxy
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
What is port 3128 used for?→
Port 3128 is the default HTTP proxy port of Squid. IANA has 3128 registered to an unrelated service, ndl-aas.
How do I stop Squid from being an open proxy?→
Allow only defined local networks with http_access rules and finish with http_access deny all, as Squid's default configuration does. Binding to an internal address adds another layer.
Is port 3128 TCP or UDP?→
Squid accepts HTTP proxy requests over TCP on 3128. IANA lists both transports for the unrelated ndl-aas registration.
Which vulnerabilities affect the service on port 3128?→
This database lists 1 CVE related to Squid proxy, 0 of them confirmed as exploited by CISA. Examples: CVE-2026-33526.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3128 is not guaranteed to be Squid proxy. Exploited-in-the-wild data from the CISA KEV catalog (CC0).