LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-24-2006, 12:28 AM   #1
raja1979
LQ Newbie
 
Registered: Dec 2005
Posts: 15

Rep: Reputation: 0
Disable an Internet proxy


hi,

I have a network of 100 computers (includes 98 , 2000 ,xp) & 1 linux server (FC4 ). On the network some 30 computers have internet access and the rest do not have internet access, i have blocked there access through iptables and have droped there packets.
The problem is that i doubt that some persons might have installed proxy server & have given access to the people who should not get access to internet through the proxy .

How can i prevent this without doing anything on the clients PCs . what can i do on the linux server so that i can prevent this .

Thanks
 
Old 02-24-2006, 04:05 AM   #2
/bin/bash
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Mandrake Slackware-current QNX4.25
Posts: 1,802

Rep: Reputation: 47
Just a thought.
The 100 computers have to go through some type of switch/router. So if the switch/router is programmable then you could try to block any port traffic except what you would expect in normal everyday use.
 
Old 02-24-2006, 08:01 AM   #3
raja1979
LQ Newbie
 
Registered: Dec 2005
Posts: 15

Original Poster
Rep: Reputation: 0
But the request comes from the proxy server , because the PC is accessing the internet through the PRoxy Server . and i cannot block the access to the proxy server because that PC on which proxy server has been installed has been permitted for internet access.
 
Old 02-24-2006, 11:06 AM   #4
/bin/bash
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Mandrake Slackware-current QNX4.25
Posts: 1,802

Rep: Reputation: 47
What I was saying is you have 100 PC's and 30 can access internet. The computer which you suspect may be acting as proxy is connected to a switch or router or hub. The computer which is accessing internet through the proxy is also connected to a switch or router or hub. So tell the switch or router (most hubs are dumb and you can not program them) to only allow local traffic which you expect in everyday usage, and block all other port traffic.

So basically you are blocking the traffic between the 2 PC's.
 
Old 02-25-2006, 02:23 AM   #5
raja1979
LQ Newbie
 
Registered: Dec 2005
Posts: 15

Original Poster
Rep: Reputation: 0
I have two switches but they are not manageable switches . so i cannot filter using the switch.
 
Old 02-26-2006, 09:22 AM   #6
/bin/bash
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Mandrake Slackware-current QNX4.25
Posts: 1,802

Rep: Reputation: 47
Well I don't see any way that you can distinguish if web traffic for Computer A is actually a proxy request from Computer B. To your server it will just look like a normal web request. Sorry I can't help.

<edit>However using something like Ethereal you may be able to locate the computers which are acting as proxy servers. But the only way to stop it will involve accessing the client.

Last edited by /bin/bash; 02-26-2006 at 09:25 AM.
 
Old 02-27-2006, 12:00 AM   #7
raja1979
LQ Newbie
 
Registered: Dec 2005
Posts: 15

Original Poster
Rep: Reputation: 0
How can i detect the proxy packets using ethereal

do they add some tag ?????????????

PLs Help
 
Old 02-28-2006, 12:33 AM   #8
raja1979
LQ Newbie
 
Registered: Dec 2005
Posts: 15

Original Poster
Rep: Reputation: 0
Any Ideas ?????????????????????/
 
Old 03-02-2006, 03:45 AM   #9
/bin/bash
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Mandrake Slackware-current QNX4.25
Posts: 1,802

Rep: Reputation: 47
Just as an example.
If you see Computer B making port 80 requests to Computer A then you would suspect Computer A is acting as proxy for Computer B.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
squid proxy server configuration & distribution of internet without proxy gaurav_gupta082 Linux From Scratch 2 07-31-2010 11:25 AM
Can I Disable Proxy usage? Noerr Linux - Networking 1 08-09-2004 08:10 AM
How do you disable going through a proxy in Debian? sanfran49 Linux - Software 2 02-12-2004 04:14 PM
How do you disable the internet? TippyToes Linux - Software 6 01-15-2004 11:29 PM
how to disable proxy using squid??? deepalic Linux - Networking 1 11-28-2001 01:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration