[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [afnog] Squid 2.4
- To: <muthonid at excite.com>, <afnog at afnog.org>
- Subject: RE: [afnog] Squid 2.4
- From: "Mark Tinka" <mtinka at africaonline.co.ug>
- Date: Thu, 7 Aug 2003 15:00:55 +0300
- Content-Type: multipart/mixed; boundary="===============15716057789979265=="
- Delivered-To: afnog-archive at lists.eahd.or.ug
- Delivered-To: afnog at afnog.org
- Importance: Normal
- In-Reply-To: <20030807104824.CB63F8AEAC at xmxpita.excite.com>
- List-Archive: <http://listserv4.cfi.co.ug/pipermail/afnog>
- List-Help: <mailto:afnog-request at afnog.org?subject=help>
- List-Id: The AfNOG general discussion list <afnog.afnog.org>
- List-Post: <mailto:afnog at afnog.org>
- List-Subscribe: <http://listserv4.cfi.co.ug/mailman/listinfo/afnog>,<mailto:afnog-request at afnog.org?subject=subscribe>
- List-Unsubscribe: <http://listserv4.cfi.co.ug/mailman/listinfo/afnog>,<mailto:afnog-request at afnog.org?subject=unsubscribe>
- Organization: Africa Online Uganda Limited
- Reply-To: mtinka at africaonline.co.ug
- Sender: afnog-bounces at afnog.org
Title: Message
Wouldn't you
rather secure the server, either by ensuring no unnecessary logins, usernames
and passwords are available on the box or better, making a clean install with
the knowledge that you did a neat job and know everything about the
box?
You can then
resume your Squid service on the same IP [after confirming with your upstream],
or use another IP address you think the don't filter.
Either way,
you need to feel secure about the security of your box. There's no telling how
much damage has been done if you feel it's been compromised.
Regards,
Mark Tinka - CCNA
Network Engineer, Africa Online Uganda
I have a problem with squid at one of my
sites.
Squid is running as root and nobody (FreeBSD).When i start
squid,it starts with two other sub-processes: (squid)(squid) and
(unlinkd)(unlinkd) both owned by nobody. I have noticed that requests
made from this server do not go past our national backbone and on
contacting my service provider (the backbone) they said that a filter
had been put on this IP. Now i am sure one squid is not legitimate
because he says that a squid running on that IP has been
compromised.
I need to know which is and how to stop the wrong
squid and bar anyone from starting such a service.It is likely to be an
internal person.
|
__________________________________________________
This is the Africa Network Operators' Group(AfNOG)
technical discussion list.
The AfNOG website is: <http://www.afnog.org>