LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-23-2004, 09:57 PM   #1
ms662412
LQ Newbie
 
Registered: Jun 2004
Posts: 1

Rep: Reputation: 0
Adware Blocking Router


I know ipfiltering with iptables is no problem, but after doing some research, I've seen no definate answer that this can be done with software that's currently out there under the GNU license. I'd like to build a filtering router for my local network of M$ machines so that I won't have to deal or worry with adware. I'd love for it to block all jscript, activex, cookies, ads, and worms/trojans with live filtering. Anyone got any ideas. Btw, I am a newb to linux so don't hurt me too much
 
Old 06-23-2004, 10:15 PM   #2
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Arctic
Distribution: Fedora, Debian, OpenSuSE and Android
Posts: 1,820

Rep: Reputation: 46
We have been very successful in reducing the adware, advertisements, and other such filth our users see on the web. While I do maintain some ipfiltering with my iptables firewalls, Squid and it's wonderful cousin SquidGuard have really made the difference.

Here is how it works:

Most of the major spyware apps that you see on a corporate LAN originate on a handful of domains. The same is true for most advertisements, pop-ups and embedded. Once you figure out where they originate, blocking becomes easier.

Set up Squid to proxy the web for your network.
Set up SquidGuard (keep those blacklists current)
Create a custom blacklist (domains file and url file) and store them with the default ones.
Set up Saint and/or Sarg to monitor Squid usage.

Each time you find spyware on a pc, check sarg to see where the machine was going on the web. You should see connections to the same servers over and over again (Ad fetching and updating and telling the scum who wrote it where you surf). If you are not sure of a url, try it in a browser, they normally will display an error.

After a few weeks you will have a pile of urls used by the scumware which you simply add to your custom url file discussed above.

Once you get comfortable blocking spyware, create another custom file for ad-servers like doubleclick and the like.

While the above wont stop spyware from installing itself, or being installed, it will prevent them from downloading pop-up ads and other scumware.
 
Old 05-25-2005, 05:32 PM   #3
rozz
LQ Newbie
 
Registered: Jan 2005
Location: Beirut - Lebanon
Distribution: Fedora
Posts: 18

Rep: Reputation: 0
Quote:
Set up Saint and/or Sarg to monitor Squid usage.
I know about Sarg, but what is Saint? I tried to google on that.
Beside having to do acrobatic queries to avoid christian saints, most of the pages in the result did not have the world saint in them! (google bug or what?). That was quite irritating.

Bottom line is I did not find any saint. So I thought, maybe you did a spelling mistake?

Last edited by rozz; 05-25-2005 at 05:40 PM.
 
Old 05-28-2005, 10:06 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
i've heard of this saint, but i'm not sure if it's the one you're talking about:

http://www.saintcorporation.com/prod...nt_engine.html
 
Old 05-29-2005, 04:56 AM   #5
rozz
LQ Newbie
 
Registered: Jan 2005
Location: Beirut - Lebanon
Distribution: Fedora
Posts: 18

Rep: Reputation: 0
Tanks for the link. I took a look at this saint ("Security Administrator's Integrated Network Tool"), read some of the website articles and carefully examined their online demo, yet I could not find anything related to squid.
 
Old 05-29-2005, 05:30 AM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Re: Adware Blocking Router

Quote:
Originally posted by ms662412
I'd love for it to block all jscript, activex, cookies, ads, and worms/trojans with live filtering.
sounds like this is what you are looking for: http://www.privoxy.org/

or maybe a simple squid plugin will satisfy your needs: http://adzapper.sourceforge.net

as for the worms/trojans, you could try this plugin: http://viralator.sourceforge.net/

you could make it work with the clamav scanner: http://www.clamav.net

there's also virus-scanning plugins for dansguardian, for example:

http://www.pcxperience.org/dgvirus/

http://www.harvest.com.br/asp/afn/dg.nsf

just my ...


Last edited by win32sux; 05-29-2005 at 05:34 AM.
 
Old 05-29-2005, 05:32 AM   #7
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally posted by rozz
Tanks for the link. I took a look at this saint ("Security Administrator's Integrated Network Tool"), read some of the website articles and carefully examined their online demo, yet I could not find anything related to squid.
yeah, me neither... but it's the only saint i'd ever heard of...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Shouldn't Adware be illegal or something? fenderman11111 General 5 09-20-2004 11:06 PM
Linksys Router Blocking Ports BrianW Linux - Networking 2 03-03-2004 12:37 AM
Stopping/Blocking PCs infected with MS BLASTER Worm (RH 6 Gateway/Router) smartcard Linux - Security 1 11-06-2003 01:02 PM
Netgear router blocking website when using internal network esteeven Linux - Networking 8 09-30-2003 07:48 AM
Spyware/Adware Jabber63 Linux - Software 1 08-10-2003 05:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration