Search squid archive

Re: spmmer abusing my proxy server

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



mån 2007-05-07 klockan 02:06 +1200 skrev Amos Jeffries:

> Yes, to find the culprit you will have to check your log. At least 
> google provide you some helpful info:
>     Posted:  5 May 2007  03:11:15 GMT
>     User-Agent: G2/1.0
>     X-HTTP-UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; 
> SV1),gzip(gfe),gzip(gfe)
>     X-HTTP-Via: 1.1 myproxy.com:3128 (squid/2.6.STABLE9)
> 
> Look for a CONNECT or similar method to port 119. If you find one it's 
> as easy as adding a port deny to your squid acls.

The post was via a HTTP to NNTP gateway, not using CONNECT. To find the
offender you need to look for POST requests to that google HTTP to NNTP
gateway..

Regards
Henrik

Attachment: signature.asc
Description: Detta =?ISO-8859-1?Q?=E4r?= en digitalt signerad meddelandedel


[Index of Archives]     [Linux Audio Users]     [Samba]     [Big List of Linux Books]     [Linux USB]     [Yosemite News]

  Powered by Linux