RE: [squid-users] Someone's using my cache?

From: Adam Carter <Adam.Carter_at_optus.com.au>
Date: Wed, 12 Nov 2008 13:45:48 +1100

> Yesterday, I wanted to get back to the cache and saw a great
> deal of traffic I/O on the cache but the weird part was that
> none of it was for or on my network. It looked like I've been
> used as some sort of payment gateway for a short while :).
> Anyhow, I do have firewall security in place,

Assuming the squid box is inside your firewall then your firewall policy is incorrect. It should not allow connections from the internet to your squid box. Depending on how your network's setup that's usually the simplest thing to change.

Or if you're squid is dual homed, stop squid from running on the dirty interface by specifying the internal interface only;
#http_port 3128
http_port 192.168.1.1:3128

Or otherwise you'll need to setup an ACL listing all your internal networks and restrict access to that only.
Received on Wed Nov 12 2008 - 02:45:48 MST

This archive was generated by hypermail 2.2.0 : Wed Nov 12 2008 - 12:00:03 MST