LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-06-2009, 02:08 AM   #1
kirukan
Senior Member
 
Registered: Jun 2008
Location: Eelam
Distribution: Redhat, Solaris, Suse
Posts: 1,278

Rep: Reputation: 148Reputation: 148
is there any possibility to attack squid proxy server?


My squid server receiving http request frequently from a particular outside IP. I got tcpdump and analyzed packets, We do not send any request from our LAN to that Outside IP(actually outside ip sending http request to my squid server), is this kind of any attack (like spoofing or DoS attack)?? Please help me to shortout this problem
Thanks.
 
Old 03-06-2009, 02:26 AM   #2
JulianTosh
Member
 
Registered: Sep 2007
Location: Las Vegas, NV
Distribution: Fedora / CentOS
Posts: 674
Blog Entries: 3

Rep: Reputation: 90
How is your squid proxy server configured? Is it firewalled? Is it listening for proxy requests on the internet facing interface?

If you can attach a copy of the pcap data, it would help us determine what kind of traffic it is. It could be typical noise, scans, or an active attack... hard to say without seeing the pcap.
 
Old 03-06-2009, 03:13 AM   #3
kirukan
Senior Member
 
Registered: Jun 2008
Location: Eelam
Distribution: Redhat, Solaris, Suse
Posts: 1,278

Original Poster
Rep: Reputation: 148Reputation: 148
I configured proxy as a transparent proxy and i redirect port 80 request to port 3128, necessary ports are allowed and all other traffic droped in filter table
Ex-
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
 
Old 03-06-2009, 03:36 AM   #4
JulianTosh
Member
 
Registered: Sep 2007
Location: Las Vegas, NV
Distribution: Fedora / CentOS
Posts: 674
Blog Entries: 3

Rep: Reputation: 90
Is the squid service bound to the external-internet-facing NIC? And are their any iptables rules that would allow traffic from the internet to access the proxy service? Is so, you could be placing yourself in some legal jepardy.

As for being attacked though, Internet facing NICs receive directed and blind attacks constantly.

We cant address any of that without the pcap data and knowing exactly what services are being made available on the server.

Just to be clear so we dont go back and forth on this:

1) Post your squid.conf
2) Post your iptables rules
3) Post your pcap data of the attacks you believe are happening.
4) Post the output of your NIC configurations: 'ifconfig -a'
 
Old 03-06-2009, 08:52 AM   #5
ledow
Member
 
Registered: Apr 2005
Location: UK
Distribution: Slackware 13.0
Posts: 241

Rep: Reputation: 34
More info required.

However, it sounds like external packets are being routed to the Squid process, which SHOULD NOT be happening unless you designed it that way. You've probably messed up the iptables or redirection rules so that either port 3128 is open to the world, or external traffic touching your port 80 is actually sent to your Squid process, which is dangerous and stupid if you don't know that's happening (you've just made yourself an anonymous web proxy for anyone on the Internet).
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
squid proxy server configuration & distribution of internet without proxy gaurav_gupta082 Linux From Scratch 2 07-31-2010 11:25 AM
Using ISA Server as Parent Proxy and want to setup Squid as dwonstream proxy tauseef1 Red Hat 1 04-09-2008 01:03 AM
squid(proxy server) pankajkarde Linux - Server 1 03-13-2007 03:51 PM
Linux DOS Attack Possibility chereth Linux - Security 2 02-09-2006 12:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration