Koozali.org: home of the SME Server

Squid Web Proxy Security Issue

Bob Wallman

Squid Web Proxy Security Issue
« on: March 06, 2002, 08:51:23 PM »
I found this web site on Insecure Web Proxy Servers and Squid is mentioned:

http://linux.oreillynet.com/pub/a/linux/2002/02/25/insecurities.html#squ

I'm not sure of the Squid version in 5.1.2.  Does anyone know if 5.1.2 is affected by this?

Filippo Carletti

Re: Squid Web Proxy Security Issue
« Reply #1 on: March 06, 2002, 09:04:06 PM »
SME squid is affected, but only local users could "attack" it.
SME firewalls port 3128 from outside.

Bob Wallman

Re: Squid Web Proxy Security Issue
« Reply #2 on: March 06, 2002, 09:08:08 PM »
I work for a School Division and I wouldn't put anything past some of the students.  I wonder if an update will be made available for this or is there something else I could do?

Filippo Carletti

Re: Squid Web Proxy Security Issue
« Reply #3 on: March 06, 2002, 09:14:47 PM »
Oops. I was thinking about a school as the only example of problematic env.
Install squid errata from RedHat 7.1.
http://www.redhat.com/support/errata/RHSA-2002-029.html

jehu

Re: Squid Web Proxy Security Issue
« Reply #4 on: March 06, 2002, 09:56:01 PM »
i am not sure if I understand what you are saying. Should I update squid. Can it be attacked from outside.

Thanks,
Jehu.

Charlie Brady

Re: Squid Web Proxy Security Issue
« Reply #5 on: March 06, 2002, 11:42:54 PM »
jehu wrote:
 
> i am not sure if I understand what you are saying. Should I
> update squid. Can it be attacked from outside.

Filippo is saying that squid cannot be attacked from the outside, and that you can update squid if you feel you should (for example, if you think that your internal users might be malicious).

And I agree with him.

Charlie

jehu

Re: Squid Web Proxy Security Issue
« Reply #6 on: March 06, 2002, 11:56:50 PM »
Thanks, the only internal user is me. So I won,t  be attacking the Squid.

Thanks again,
Jehu

Dean Mumby

Re: Squid Web Proxy Security Issue
« Reply #7 on: March 08, 2002, 02:35:46 PM »
Why is SME using such and old version of squid the latest stable is 2.4STABLE4 and we are using 2.3STABLE4 surely there must be some important improvements ?

Dean

Filippo Carletti

Re: Squid Web Proxy Security Issue
« Reply #8 on: March 08, 2002, 04:32:02 PM »
2.3.STABLE4 was included in RedHat 7.1 upon which SME is based.
See http://www.squid-cache.org/Versions/v2/2.4/ChangeLog.txt for improvements / fixes.