Re: [squid-users] Security Issue with Squid (help!)

From: Henrik Nordstrom <[email protected]>
Date: Mon, 30 Jul 2007 16:06:10 +0200

On tor, 2007-07-26 at 21:47 -0700, Reid wrote:
> I've only been running this squid server for about a week so I doubt this is an unusual problem.
> Can anyone help??
>
> More observations:
>
> 1- I suspect that this problem began when someone using my proxy was doing a "click on a bunch of
> sites to make money" type program. Now, when regular visitors are surfing through my squid, pages
> that I believe the user had visited are loading within iframes on random pages for other squid
> users - in fact, almost every page is loading the iframed websites, even if they are pages that
> the squid server doesn't have in cache and has never visited.

Which Squid version?

> 2- My original observation that hitting refresh would fix the problem is not true. The iframes can
> appear even after refreshing.

what do access.log say when you refresh the page?

Do the urlbar indicate the right site, or the fake one?

What do you get if you try requesting a such iframed site using
squidclient?

Regards
Henrik
Received on Mon Jul 30 2007 - 08:06:22 MDT

This archive was generated by hypermail pre-2.1.9 : Wed Aug 01 2007 - 12:00:04 MDT