LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-29-2009, 08:28 AM   #31
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380

Quote:
Originally Posted by Net_Spy View Post
Im using squid in tranparent mode
Transparent mode doesn't apply to HTTPS.

You already confirmed to us that your clients are NOT using Squid for HTTPS when you posted this:
Quote:
Originally Posted by Net_Spy View Post
when accessing https://www.facebook.com I didnt see its log in squid seems like it is bypassing squid
Quote:
Originally Posted by Net_Spy View Post
and apply that iptbales rule but it block all requests.

Last edited by win32sux; 08-29-2009 at 01:53 PM.
 
Old 08-29-2009, 08:13 PM   #32
Net_Spy
Member
 
Registered: Nov 2006
Posts: 119

Original Poster
Rep: Reputation: 17
Thank you all for your support to helping me on this issue. since I fingure out ,it is not possible to track https in transparent mode of squid .


Regards
Net_Spy
 
Old 08-29-2009, 08:53 PM   #33
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by Net_Spy View Post
Thank you all for your support to helping me on this issue. since I fingure out ,it is not possible to track https in transparent mode of squid .
For the record, it's not just Squid. This is a natural limitation of all proxy servers. Did you search LQ before starting this thread? I ask because this has been discussed here before. That said, the words "not possible" might be a bit too much, since you could always start issuing your own certificates (and get clients to accept them) in order to gain the ability to transparently proxy HTTPS traffic (MITM attack). It's a nasty/dangerous practice, but it seems to be an increasingly common one in corporate environments. Personally, I've never done it (and have no plans to), since it isn't compatible with my ethical standards.

Last edited by win32sux; 08-29-2009 at 09:00 PM.
 
Old 08-30-2009, 06:09 PM   #34
Net_Spy
Member
 
Registered: Nov 2006
Posts: 119

Original Poster
Rep: Reputation: 17
Thanks win32sux well I'm not going to do that , it isn't a good idea . well If I found any reliable solution I will add it in this thread .

Regards
Net_Spy
 
Old 11-24-2010, 02:21 PM   #35
helmikuu
LQ Newbie
 
Registered: Jun 2010
Posts: 4

Rep: Reputation: 0
In my case, I been blocking facebook.com in pfsense server through squid. Although it is working perfectly , some users have found a way out by accessing the same url with https in place of http. To solve the problem I need to block https www.facebook.com in firewall rules.

Please click my simple tutorial on how to block https www.facebook.com
 
Old 11-29-2010, 04:57 AM   #36
Net_Spy
Member
 
Registered: Nov 2006
Posts: 119

Original Poster
Rep: Reputation: 17
Thanks for your valueable response. This is very old thread . One thing I would like to share is that there is not a way to block https via squid when you are running it in transparent mode . if your proxy isnt in transparent mode then there is easy to go with .

Regards
Net_Spy
 
Old 11-29-2010, 06:01 AM   #37
chickenjoy
Member
 
Registered: Apr 2007
Distribution: centos,rhel, solaris
Posts: 239

Rep: Reputation: 30
@Net_Spy

Tested this on squid 2.6STABLE on centos 5.5 and although I don't get the usual error message of 'access denied' like when accessing http://www.facebook.com.

when I access https://www.facebook.com; it shows a "proxy server refused connection" which also indirectly does what I want it to do....

did yours show similar behavior?

EDIT: whops; my squid was NOT in transparent mode. that is why. ^^

Last edited by chickenjoy; 11-29-2010 at 06:23 AM.
 
1 members found this post helpful.
Old 12-01-2010, 04:22 AM   #38
Net_Spy
Member
 
Registered: Nov 2006
Posts: 119

Original Poster
Rep: Reputation: 17
Finally Ive solved my issue Im able to block https as well as streaming on facebook if it is allow . Im running squid in transparent mode so I had to use IPtables to block facebook completely .

If any one needs the solution let me know.

Regards
Net_Spy

Last edited by Net_Spy; 09-05-2011 at 12:18 AM.
 
1 members found this post helpful.
Old 01-14-2012, 12:17 PM   #39
kaustuva
LQ Newbie
 
Registered: Sep 2008
Posts: 1

Rep: Reputation: 1
Smile Urgent Help

Quote:
Originally Posted by Net_Spy View Post
Finally Ive solved my issue Im able to block https as well as streaming on facebook if it is allow . Im running squid in transparent mode so I had to use IPtables to block facebook completely .

If any one needs the solution let me know.

Regards
Net_Spy
Hi Net_Spy,

I am hopeless to block https traffic with some exception to allow some banking site.
I have blocked https traffic with iptables. I am using squid dansguardian.
Please suggest me, how you can block it.
Please replay me on my personal mail id: kaustuvabedant@gmail.com

Thanks and regards
Kaustuva
 
1 members found this post helpful.
Old 02-15-2012, 04:21 AM   #40
Jambaz
LQ Newbie
 
Registered: Feb 2012
Posts: 6

Rep: Reputation: Disabled
Quote:
Originally Posted by kaustuva View Post
Hi Net_Spy,

I am hopeless to block https traffic with some exception to allow some banking site.
I have blocked https traffic with iptables. I am using squid dansguardian.
Please suggest me, how you can block it.
Please replay me on my personal mail id: kaustuvabedant@gmail.com

Thanks and regards
Kaustuva


Hi Kaustuva ,
I also need to resolve this problem , i use squid in transparent mode..i have read about iptables , you have resolved your problems ?

P.S.:If anyone have found the solution contact me at gibbybia@hotmail.com ( sorry for the e-mail )

Last edited by Jambaz; 02-15-2012 at 04:57 AM.
 
Old 02-22-2012, 01:24 AM   #41
Net_Spy
Member
 
Registered: Nov 2006
Posts: 119

Original Poster
Rep: Reputation: 17
@Jambaz ,

This is very old thread , but yet I'm glad that it is useful to people who seeks the solution to block https . I will get back to you with solution. if you provide some details.


Retards
Net_Spy
 
1 members found this post helpful.
Old 02-23-2012, 02:04 PM   #42
Jambaz
LQ Newbie
 
Registered: Feb 2012
Posts: 6

Rep: Reputation: Disabled
Quote:
Originally Posted by Net_Spy View Post
@Jambaz ,

This is very old thread , but yet I'm glad that it is useful to people who seeks the solution to block https . I will get back to you with solution. if you provide some details.


Retards
Net_Spy


Hi Net_Spy , me and Kaustuva are very happy to read your words ,
I tell you all you need , i use squid in transparent mode , the version is the 2.7stable 9 ( on Ubuntu ) with squidGuard , the https if i put the settings in the browser the https don't function , but you know that is not a solution , first because the user can set the settings manually ( especially on Win client , edit some key ) , second because they can use some programs like ultrasurf and they resolve https links.....i can denied all https connections , but i need that for banking and other utilietis and so i need only to apply the filter on this connection , or redirecting the https on http...tell me my friend Net_Spy the solution that you have found :-)

Regards
 
Old 02-23-2012, 02:56 PM   #43
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by Jambaz View Post
Hi Kaustuva ,
I also need to resolve this problem , i use squid in transparent mode..i have read about iptables , you have resolved your problems ?
P.S.:If anyone have found the solution contact me at ( sorry for the e-mail )
...and....
Quote:
Originally Posted by kaustuva
I am hopeless to block https traffic with some exception to allow some banking site. I have blocked https traffic with iptables. I am using squid dansguardian. Please suggest me, how you can block it. Please replay me on my personal mail id
You both re-opened a thread that was closed for TWO YEARS, and which was originally older than that, which isn't a good thing to do; post your own thread for your own questions. Second, this isn't the place to come for personalized, one-on-one email tech support. This is a COMMUNITY forum...if you don't participate here, then you need to PAY someone to spoon-feed you the answers to your email or give them to you over the phone.

As net_spy was told in this thread (and the OTHER thread opened with the same question), there are ways to perform some functions with https, but again you need to THINK about what https IS, and why a proxy server won't work for it. The suggestions in this thread are valid...follow them.

May want to read the UPDATED thread: http://www.linuxquestions.org/questi...curity-930878/
 
Old 01-18-2016, 11:24 AM   #44
hhhrrrzzzzzzzzz
Member
 
Registered: Jan 2016
Posts: 47

Rep: Reputation: Disabled
Hey i use "SQUID 2.7.STABLE8" under windows for several reasons.
the Domain Blocking from the example here work.

But how to block an SSL URL? like:
Code:
acl badsites url_regex -i ^%%%%%%%%%/.*/opener.*.mp4
That blocks an Ads Video who is played before the Clip come.
thanks!!!


(sorry i have to please the url with %)
 
Old 01-18-2016, 12:05 PM   #45
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by hhhrrrzzzzzzzzz View Post
Hey i use "SQUID 2.7.STABLE8" under windows for several reasons.
the Domain Blocking from the example here work.

But how to block an SSL URL? like:
Code:
acl badsites url_regex -i ^%%%%%%%%%/.*/opener.*.mp4
That blocks an Ads Video who is played before the Clip come.
thanks!!!

(sorry i have to please the url with %)
Read the LQ Rules...you have re-opened a THREE YEAR OLD THREAD, to post your own question...which was closed for TWO YEARS before the last couple of folks re-opened it.

They both *CLAIM* to have a 'solution', but (not surprisingly), haven't ever posted it, because it doesn't exist. Check the previous responses/links in this very thread, for why this won't work.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to block https sites through ACL in squid avi_tokade Linux - Newbie 5 04-12-2011 05:53 PM
how to block gmail & gtalk (https traffic)using squid satishmali1983 Linux - Server 4 06-25-2009 01:22 AM
unable to block all website except www.onlinesbi.com in squid nirmal1100 Linux - Newbie 0 03-30-2009 04:53 AM
How can I block HTTPS packets with iptables/Squid? sanjee Linux - Security 5 10-29-2008 04:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration