LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-15-2011, 10:11 AM   #1
abdulrhman
LQ Newbie
 
Registered: Aug 2009
Posts: 3

Rep: Reputation: 0
Squid and blocking GET HTTP method for phishing purpose


Hey all,

I got this idea about making users in my network aware of phishing attacks "en.wikipedia.org/wiki/Phishing"

so i got a list containing phishing websites, then i defined ACL that's block POST requests.

so the scenario as follows .. user enter the phishing website .. then he fill the form and when hey try to submit .. a blocking page will show up and tell him he was under phishing attack.

this is screenshot of the blocking message

http://dl.dropbox.com/u/196664/Screenshot-10.png

So, everything worked as i planned .. except for websites that uses HTTP GET method !

And if i blocked GET method .. the whole website will not be loaded from the first time.

i tried to analysis Squid access.log to find a way to block them ,, but i couldn't

this is my ACL in squid.conf
--

#phishing access
acl phishing dstdomain "/etc/squid/phishing-sites"
acl http_method method POST

Phishing Sites
http_access deny phishing http_method
--

Anyone got an idea ?

Regards,
 
Old 03-15-2011, 05:17 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
I'like the idea og blocking posts, but at the same time, if it's a phishing site, why would you want any access to it at all, regardless of the http method?
 
Old 03-15-2011, 06:25 PM   #3
abdulrhman
LQ Newbie
 
Registered: Aug 2009
Posts: 3

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by acid_kewpie View Post
I'like the idea og blocking posts, but at the same time, if it's a phishing site, why would you want any access to it at all, regardless of the http method?
I wanna teach the user about phishing. I want to tell he almost be a victim for phishing. so next time he will double check with url and be careful.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Squid+DansGuardian not working properly. squid blocking sites that should be linuxlover.chaitanya Linux - Server 13 11-10-2014 10:34 AM
Blocking websites - preferred method? linuxbird Linux - Networking 9 05-21-2010 09:24 AM
fail2ban best method of blocking brute force attempts? mrtwice Linux - Security 3 12-09-2008 10:52 AM
SQUID for blocking yahoo and msn [inc squid.conf] chrisfirestar Linux - Security 10 03-03-2008 08:33 AM
LXer: Phishing for Open Proxies: Baby Squid Hooked In Under 18 Hours LXer Syndicated Linux News 0 01-26-2006 12:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:47 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration