[squid-users] How to block shoutcast streams?

From: Boniforti Flavio <boniforti@dont-contact.us>
Date: Tue, 15 Nov 2005 15:55:05 +0100

Hello all.
I'm getting reports which show huge traffic amounts on some http IP
addresses. These point to ports like 9000, 8000, 8100, 9720, and the
like. When I put those URLs in the browser, I get to some shoutcast
servers (let's take as an example: http://213.35.156.16:9000/). How may
I block this sort of streaming media?
Here the relevant log lines:

1131956633.216 7236 10.167.211.62 TCP_MISS/600 298294 GET
http://213.35.156.16:9000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131965732.540 917 10.167.211.62 TCP_MISS/600 25021 GET
http://213.35.156.16:9000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131965815.003 81204 10.167.211.62 TCP_MISS/600 2093292 GET
http://213.35.156.16:9000/ -
TIMEOUT_FIRST_UP_PARENT/proxy.reteunitaria.piemonte.it -
1131982736.548 6082 10.167.211.62 TCP_MISS/600 362948 GET
http://213.35.156.16:9000/ -
TIMEOUT_FIRST_UP_PARENT/proxy.reteunitaria.piemonte.it -
1131985079.527 2613 10.167.211.62 TCP_MISS/600 163257 GET
http://213.35.156.16:8000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131985825.545 2244 10.167.211.62 TCP_MISS/600 106951 GET
http://213.35.156.16:9000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131986644.367 7009798 10.167.211.163 TCP_MISS/600 168504426 GET
http://213.35.156.16:8000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -

As you can see, there's nothing more than the URL, no MIME type
indication at all!

Any help would be appreciated.

Thanks in advance,

-- 
-----------------------------------
Boniforti Flavio
Provincia del Verbano-Cusio-Ossola
Ufficio Informatica
Tecnoparco del Lago Maggiore
Via dell'Industria, 25
28924 Verbania
-----------------------------------
Received on Tue Nov 15 2005 - 07:55:17 MST

This archive was generated by hypermail pre-2.1.9 : Thu Dec 01 2005 - 12:00:09 MST