Re: [squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-02-02 Thread Giles Coochey
On 01/02/2011 11:13, Amos Jeffries wrote: The CVE is applicable to all proxies doing interception. They generate their URL from the Host: header instead of the TCP link details from the client. Neither being a reliable source of information. The one saving grace so far is that the client TCP

Re: [squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-02-01 Thread Amos Jeffries
On 02/02/11 01:27, Pandu Poluan wrote: On Tue, Feb 1, 2011 at 18:15, Amos Jeffries wrote: On 01/02/11 19:58, Pandu Poluan wrote: On Tue, Feb 1, 2011 at 13:36, Amos Jeffries wrote: On 01/02/11 16:29, Pandu Poluan wrote: Hello, I want to configure SQUID as a transparent proxy, but on a sepa

Re: [squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-02-01 Thread Pandu Poluan
On Tue, Feb 1, 2011 at 18:15, Amos Jeffries wrote: > On 01/02/11 19:58, Pandu Poluan wrote: >> >> On Tue, Feb 1, 2011 at 13:36, Amos Jeffries  wrote: >>> >>> On 01/02/11 16:29, Pandu Poluan wrote: Hello, I want to configure SQUID as a transparent proxy, but on a separate b

Re: [squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-02-01 Thread Amos Jeffries
On 01/02/11 21:48, Giles Coochey wrote: On 01/02/2011 07:36, Amos Jeffries wrote: The whole of section 6.1 is a major security vulnerability "don't do it!" situation. Read CVE-2009-0801 for an explanation of what malware can do to trivially spread themselves across your whole client base. The

Re: [squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-02-01 Thread Giles Coochey
On 01/02/2011 07:36, Amos Jeffries wrote: The whole of section 6.1 is a major security vulnerability "don't do it!" situation. Read CVE-2009-0801 for an explanation of what malware can do to trivially spread themselves across your whole client base. The currently available Squid do permit it

Re: [squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-01-31 Thread Amos Jeffries
On 01/02/11 16:29, Pandu Poluan wrote: Hello, I want to configure SQUID as a transparent proxy, but on a separate box from the Linux gateway (both boxes using Ubuntu Server 10.04) I found this howto: http://www.faqs.org/docs/Linux-mini/TransparentProxy.html Now, my questions are: 1. Is the ho

[squid-users] SQUID transparent, HTTP/1.0, HTTP/1.1

2011-01-31 Thread Pandu Poluan
Hello, I want to configure SQUID as a transparent proxy, but on a separate box from the Linux gateway (both boxes using Ubuntu Server 10.04) I found this howto: http://www.faqs.org/docs/Linux-mini/TransparentProxy.html Now, my questions are: 1. Is the howto (esp. sections 6.2 and 6.3) still app