On Tue, Sep 05, 2006 at 07:34:13AM +0700, Agi Subagio wrote:
> lihat website ini 
> http://help.yahoo.com/help/us/messenger/win/signin/signin-02.html
> lalu blok port dan server2-nya melalui iptables.
> dijamin gak akan bisa konek YM lagi.

Alternatif lain, squid diset sbg proxy transparent, kemudian
edit squid.conf dan tambahkan baris2 yg ditandai dg "##" atau yg
mengandung kata "BROWSER" hasilnya seperti ini:

acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl localnet1 src 192.168.0.0/255.255.255.0
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 80          # http
acl Safe_ports port 88          # to my local webserver
acl Safe_ports port 21          # ftp
acl Safe_ports port 443 563     # https, snews
acl Safe_ports port 70          # gopher
acl Safe_ports port 210         # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280         # http-mgmt
acl Safe_ports port 488         # gss-http
acl Safe_ports port 591         # filemaker
acl Safe_ports port 777         # multiling http
acl CONNECT method CONNECT ##
acl BROWSER req_header User-Agent -i "/usr/local/squid/etc/user-agent"
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost
http_access deny !BROWSER ##
http_access allow localnet1
http_access deny all
http_reply_access allow manager
http_reply_access deny !BROWSER ##
http_reply_access allow all
icp_access deny all

Buat dulu filenya /usr/local/squid/etc/user-agent.

# cd /usr/local/squid/etc/
# touch user-agent
# squid -k reconfigure

Sekarang kita kudu "mendengarkan" pakai ngrep browser2 default mana saja
yg boleh pakai internet selain itu diblok, biasanya muncul access denied.
Cari dan install ngrep, kemudian jalankan perintah sbg root:

# ngrep -qi user-agent host ip_client_yg_buka_internet

Paling enak kita jalankan ngrep di posisi client via putty, kemudian browsing
pakai IE atau Mozilla, pasti kena access_denied. Hasil pengamatan via ngrep
nanti di masukkan ke file user-agent, contoh pengamatannya kayak ini:

Saya pakai IE 6.0.2800.

[EMAIL PROTECTED] root]# ngrep -qi user-agent host 192.168.0.114
interface: eth0 (192.168.0.0/255.255.255.0)
filter: (ip) and ( host 192.168.0.114 )
match: ser-agent

T 192.168.0.114:3123 -> 202.146.5.33:80 [AP]
  GET /kompas-cetak/0609/07/daerah/ HTTP/1.1..Accept: image/gif, 
image/x-xbitmap, image/jpeg, i
  mage/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, 
application/msword, appl
  ication/x-shockwave-flash, */*..Referer: 
http://www.kompas.co.id/kompas-cetak/0609/07/Sosok/2
  935993.htm..Accept-Language: en-us..Accept-Encoding: gzip, 
deflate..User-Agent: Mozilla/4.0 (
  compatible; MSIE 6.0; Windows NT 5.1)..Host: www.kompas.co.id..Connection: 
Keep-Alive....

User agentnya: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Biasanya kalau pakai yahoo messenger, user-agentnya:
  Mozilla.Compatible/2.0.\(WinNT;.I;.NCC/2.0\)

Memang repot sih, kita harus mantau trafik internet dg ngrep mana2 agent 
browser yg
boleh ke internet dan kemudian menuliskan user-agentnya satu demi satu ke
file /usr/local/squid/etc/user-agent
Nulisnya juga ada aturannya, jadi kayak tadi (yg boleh lewat) ditulis
begini:

# cat /usr/local/squid/etc/user-agent
Mozilla/4.0.\(compatible;.MSIE.6.0;.Windows.NT.5.1\)

Selain itu bisa memblok virus2 yg biasa jalan begitu suatu link dibuka.
Biasanya kalo kita buka situs2 warez, serial numbers dll.

Selamat berjuang !

Salam,

~yudi

NB: Topik blok akses via user-agent ini dulu pernah saya lempar ke milis
    sekitar setahun yl, kira2 april/mei 2005.


-- 
FAQ milis di http://wiki.linux.or.id/FAQ_milis_tanya-jawab
Unsubscribe: kirim email ke [EMAIL PROTECTED]
Arsip dan info milis selengkapnya di http://linux.or.id/milis

Kirim email ke