Re: [SQU] Transparent proxying with spoof'd outbound packets from cache

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Sat, 11 Nov 2000 02:35:41 +0100

Ben Efros wrote:
>
> It would be possible to improve on the transparent proxying idea by spoofing
> the source address on all outbound packets from the proxy. This way the
> _real_ www server will see the user's _real_ ip as it is presented to the
> cache.

True, and I know that at least one person have done it with a sligthly
hacked Linux version (some root-only permission checks removed) combined
with a equally slightly hacked Squid version..

Please note that even thinking of attempting something like this is ONLY
recommended if Squid is running on the internet gateway for the network.
If not then there is way to many hasards in TCP/IP networking...

--
Henrik Nordstrom
Squid hacker
--
To unsubscribe, see http://www.squid-cache.org/mailing-lists.html
Received on Fri Nov 10 2000 - 18:39:19 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:56:19 MST