Re: [squid-users] What would be the maximum ufs\aufs cache_dir objects?

2017-07-26 Thread Omid Kosari
Interesting because i was going to create a new topic like this but Eliezer read my mind ;) Nowadays i can see that the http traffic is going fewer and fewer and every day i am thinking about retiring the squid . But currently is see that most of the remaining http traffic which worth caching is

[squid-users] Cache poisoning vulnerability 3.5.23

2017-07-26 Thread Omid Kosari
Hello, Recently i have seen some Cache poisoning specially on android captive portal detection sites . My squid was 3.5.19 (from https://packages.debian.org/stretch/squid) on Ubuntu Linux 16.04 . Then i have upgraded to latest version 3.5.23 (from https://packages.debian.org/stretch/squid) and pur

Re: [squid-users] Cache poisoning vulnerability 3.5.23

2017-07-26 Thread Omid Kosari
By my experience if you see any output from following command you may be a victim grep -a 'generate_204' /var/log/squid/access.log | grep -v '/204 ' | grep -v '/000' | grep -v opera | grep -v ucweb | grep -v apple -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.

Re: [squid-users] Cache poisoning vulnerability 3.5.23

2017-07-26 Thread Amos Jeffries
On 26/07/17 23:33, Omid Kosari wrote: By my experience if you see any output from following command you may be a victim grep -a 'generate_204' /var/log/squid/access.log | grep -v '/204 ' | grep -v '/000' | grep -v opera | grep -v ucweb | grep -v apple OR, you have Android clients on your netw

[squid-users] July 25 2017 - #RIP Urlblacklist.com closed down.

2017-07-26 Thread Benjamin E. Nichols
This is a courtesy message to inform Squid Proxy users who may be using blacklists by urlblacklist.com On July 25 2017, Blacklist provider Urlblacklist.com has closed down, shut of its website, and thrown in the towel, they have refunded current subscribers and closed up shop. Also July

Re: [squid-users] How to tell HTTPS traffic is using cache from access.log in 3.5.x when using ssl_bump

2017-07-26 Thread Lei Wen
Hi Amos, Thanks a lot. It is my splice thing is blocking proxy in the middle, after using stare instead of peek, seems work though, terminal in this case is not blocking proxy in the middle? I made some change on my squid.conf, it work for http/https caching and http/https whitelist. It is workin

Re: [squid-users] How to tell HTTPS traffic is using cache from access.log in 3.5.x when using ssl_bump

2017-07-26 Thread Amos Jeffries
On 27/07/17 09:54, Lei Wen wrote: Hi Amos, Thanks a lot. It is my splice thing is blocking proxy in the middle, Sort of, yes. after using stare instead of peek, seems work though, terminal in this case is not blocking proxy in the middle? Not sure what you are asking there. Squid *is* t

Re: [squid-users] Cache poisoning vulnerability 3.5.23

2017-07-26 Thread Omid Kosari
Amos Jeffries wrote > Cache poisoning (if it is that) is a serious security issue. Please > bring the details of security problems to the *squid-bugs* mailing list > so it can be investigated and solved, rather than blind-siding everyone > with a public announcement like this. > > Amos I tried