> Are there any real bad things (tm) users authorized to use a squid cache
> could do if I would replace the default Safe_ports acl with
> something like "acl Safe_ports 1-65535"?

Yes, though what exactly they can do depends on the version of Squid.

With older Squids (1.0) they could do anything from IRC through the server
(happend to us a few weeks ago) to forge mail.

The newer Squid limits this kind of stuff a lot more: you may be able to
get away with it.... up to you. If I did enable random destination port
access I would set up a cron script that greps for ports outside the ranges
below every day: just so that you can keep an eye on things.

