RE: [squid-users] Web site got hack through squid

2004-09-04 Thread Discussion Lists
Hi Tom, People should correct me if I am wrong, however a proxy server such as squid doesn't know the difference between a legitimate web request, and a malicious one. Both can, and in most cases are required to be compliant with various networking RFC's. A malformed GET request, for instance, do

Re: [squid-users] Defined ACL is not working

2004-09-04 Thread devendra
Hello, 192.0.0.200,192.0.0.201 is client ip address which i want to block msnmessenger all at all time except 12-14. so i have define the ACL as like acl client_acl src 192.0.0.200, 192.0.0.201 acl time_acl time 12:00-14:00 http_access deny msnmessenger !time_acl client_acl The above acl is not w

[squid-users] Web site got hack through squid

2004-09-04 Thread Tom Le
Hi, I have a website that sits behind squid 2.5 and it got hack into today. Someone from this ip address, 200.148.134.206, has put few files into my website through squid. The content of the index.html is "Simiens Crew 2004 Ownz U" Here is the log from squid 1094326387.752 899375 200.148.134.2

[squid-users] Squid and OWA using SSL

2004-09-04 Thread Discussion Lists
Hi all, I have tried to search for a solution on this, and either I missed it, or it just isn't out there. I need to set up a redirector for OWA using Squid, but here are some details: 1. Users from the Internet need to connect using SSL (this is a must). 2. The connection needs to be redirected

RE: [squid-users] Hacking ntlm_auth to allow squidGuard ACLs

2004-09-04 Thread Discussion Lists
Thanks Jay, I have a test environment, so I can just try uninstalling Samba2.x, and just install Samba3 instead. I will give it a try. Thanks again! Mark > -Original Message- > From: Jay Turner [mailto:[EMAIL PROTECTED] > Sent: Friday, September 03, 2004 2:25 AM > To: [EMAIL PROTECTED]

[squid-users] squid crashes a lot

2004-09-04 Thread yance kowara
Dear all, I've got squid 2.4 stable 6 on FreeBSD 4.2. It's been running since 2002 without problem, and without changes to the environment (hardware,OS, etc). The FreeBSD box is a gateway for around 40 -50 concurrent internet users. Lately on /var/log/messages squid has exited alot due to signa

Re: [squid-users] Silly ...questio

2004-09-04 Thread Henrik Nordstrom
On Sat, 4 Sep 2004, Mohsin Khan wrote: I have just installed squid-2.5.STABLE6, when i start squid, i see only one squid process, but when some one starts browsing the child processes increas and well i count them they are 23. You are using the "aufs" cache_dir type. It is only one process still..

[squid-users] Silly ...questio

2004-09-04 Thread Mohsin Khan
I have just installed squid-2.5.STABLE6, when i start squid, i see only one squid process, but when some one starts browsing the child processes increas and well i count them they are 23. Is it the default behavior, as i have not seen it in squid-2.2 = Regards, Mohsin Khan CCNA ( Cisco C

Re: [squid-users] %i is always returing 0.0.0.0 in ERR_TOO_BIG but not in ERR_ACCESS_DENIED

2004-09-04 Thread Henrik Nordstrom
On Sat, 4 Sep 2004, Srinivasa Rao T wrote: I am using squid 2.5.6 (2.5.STABLE6) on Debian sarge, in transparent proxy mode. After setting "reply_body_max_size 200", %i in ERR_TOO_BIG is always returning 0.0.0.0 instead of client IP address. This is not implemented yet. There is even a bug repor

Re: [squid-users] Defined ACL is not working

2004-09-04 Thread Henrik Nordstrom
On Sat, 4 Sep 2004, devendra wrote: acl client_acl src 192.0.0.200,192.0.0.200 This is not correct syntax. Why the ,192.0.0.200? acl time_acl time 12:00-14:00 Ok. acl msnmessenger url_regex -i gateway.dll http_access deny msnmessenger !time_acl client_acl This should block msnmessenger all at all t

[squid-users] %i is always returing 0.0.0.0 in ERR_TOO_BIG but not in ERR_ACCESS_DENIED

2004-09-04 Thread Srinivasa Rao T
Hi, I am using squid 2.5.6 (2.5.STABLE6) on Debian sarge, in transparent proxy mode. After setting "reply_body_max_size 200", %i in ERR_TOO_BIG is always returning 0.0.0.0 instead of client IP address. But working perfectly by returning the actual client IP in ERR_ACCESS_DENIED. Could somebo

[squid-users] Defined ACL is not working

2004-09-04 Thread devendra
Hello I am trying to block msn messenger for few ip at perticular time. I have worte acl, acl given below. acl client_acl src 192.0.0.200,192.0.0.200 acl time_acl time 12:00-14:00 acl msnmessenger url_regex -i

Re: [squid-users] ip_wccp - compiled, still not working.. help...

2004-09-04 Thread Henrik Nordstrom
On Fri, 3 Sep 2004, [iso-8859-1] Mark Tinka wrote: i then configured my router interface facing the router/segment onto which my cache is located with the 'ip wccp web-cache redirect in' command, but see no action.. packets are still going out normally.. it's like the cache isn't there Your pro

Re: [squid-users] Linux Kongress 2004

2004-09-04 Thread Henrik Nordstrom
On Sat, 4 Sep 2004, unixware wrote: 2) Is squid-3 will support SMP/Hyperthreading ? No. 3) how many times it will run fast using epoll in linux kernel 2.6.x Not yet known. It is not estimated epoll will make Squid run faster as such, but it should help make sure it does not spiral down to death wh

RE: [squid-users] Trying too use user_cert acl with SQUID 2.5 + SSL patch

2004-09-04 Thread Henrik Nordstrom
On Sat, 4 Sep 2004, Fauquet, Xavier wrote: http_access allow USER-ok http_access deny USER-ko http_access deny all I tried it and now everybody is denied. Suspected this. Your USER-ok is not matching the user. Regards Henrik

RE: [squid-users] problems compiling SQUID 2.5STABLE 6 with ssl o ption

2004-09-04 Thread Fauquet, Xavier
Henrik, without the make disclean command, I got error with MD5 Making the disctclean command, I got other error messages but not with MD5 :-( I will forward to the list the error messages. Max > -Message d'origine- > De : Henrik Nordstrom [mailto:[EMAIL PROTECTED] > Envoyé : vendre

RE: [squid-users] Trying too use user_cert acl with SQUID 2.5 + S SL patch

2004-09-04 Thread Fauquet, Xavier
> > > Well, I tried the following : > > acl USER-ok CN surname.name > > acl USER-ko CN ko1.ko1 > > http_access allow USER-ok > > http_access deny USER-ko > > > > Both user can still browse. > > Anything i forgot ? > > > The acl statements is not using correct syntax. Should be > > acl USER-o

Re: [squid-users] PAM Auth

2004-09-04 Thread Henrik Nordstrom
On Fri, 3 Sep 2004, [ISO-8859-1] Carlos Simbaña wrote: I am trying to work with PAM users auth (pam_auth). In my old squid 2.5 stable 1 it works fine but in my squid 2.5 stable 6 not work. I probe with: *chown root pam_auth* *chmod u+s pam_auth* Have you also configured the "squid" PAM service? bu

Re: [squid-users] Linux Kongress 2004

2004-09-04 Thread unixware
> I need at least 2 confirmed persons intending to > attend this Squid BOF > session at the Linux Kongress to prepare the > session. > > So far it has been very silent which either means > that there is no Squid > Users attending the Linux Kongress, or that there is > no interest to > discuss

RE: [squid-users] Squid As A Daemon

2004-09-04 Thread Henrik Nordstrom
On Fri, 3 Sep 2004, Brad Taylor wrote: Squid does ask for the password right after it type: squid Does squid need the password again? Why does this work in non Daemon mode? Your Squid has no way of asking of the encryption password when you run it as a daemon unless you configure a method of as