Re: [squid-users] Defending against new attacks

From: Joel Jaeggli <joelja@dont-contact.us>
Date: Tue, 25 Sep 2001 13:12:59 -0700 (PDT)

among other things filtering downloads of executables, will prevent
microsoft live-update from working properly...

joelja

On Tue, 25 Sep 2001, Brian M Dial wrote:

> With the nimda virus semi-behind now, I'm looking at a way of protecting
> from something like this in the future. The only thought I've had so
> far is a way of filtering out executables from being downloaded from the
> web.
>
> I've looked at some threads similar to this in the logs but I have some
> questions. Is there any better way then using a url pattern match to
> handle this? I know I can use url_regex \.eml or \.exe or any
> executable but is this the right way to be doing it? I've noticed that
> since I used it to filter .exe, I've had a few problem with people
> browsing sites that use .exe for their cgi extension and squid will deny
> the client even though it's not trying to download it.
>
> Is using url_regex based acl's really the best way to be doing this?
>
> Thanks for any input,
>
> -Brian
>
>

-- 
--------------------------------------------------------------------------
Joel Jaeggli				       joelja@darkwing.uoregon.edu
Academic User Services			     consult@gladstone.uoregon.edu
     PGP Key Fingerprint: 1DE9 8FCA 51FB 4195 B42A 9C32 A30D 121E
--------------------------------------------------------------------------
It is clear that the arm of criticism cannot replace the criticism of
arms.  Karl Marx -- Introduction to the critique of Hegel's Philosophy of
the right, 1843.
Received on Tue Sep 25 2001 - 14:12:49 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:02:29 MST