PDA

View Full Version : Squid Proxy Hacked?


toddba
08-22-2003, 01:00 AM
We have been searching for some missing BW and I have stumbled upon the fact that the Squid Proxy on our Star OS server is going nuts. It is both uploading and downloading constantly.

I have disabled the proxy completely. I have added firewall rules to deny all incoming and outgoing traffic. (This at least stopped the outgoing). I have even completely removed the ip address that was associated with the proxy. It continues to generate traffic.

I am at my wits end. Could someone please help shut down this traffic.

If someone would contact me via voice I would be happy to let you get in our server and see what the hell is going on. US number 970-590-6127.

Thanks in advance for your help.

Todd Barber
Skylink Broadband Internet
toddbarber@slbbi.com

lonnie
08-22-2003, 01:13 AM
email me with the IP and password. I'll be up for another 20 minutes or so. If I miss it tonight I will check first thing in the morning.

kishvet
08-22-2003, 03:56 PM
Just had the same thing last week. Shut off outside access to port 8080 and the bw magically reappeared. Still see some ips from Japan and China trying, but very little traffic. Uncomment the line in the standard fw config. If your situation is different, please let us know. Don't want to miss doing something we should be doing. Thanks.

tony
08-22-2003, 04:15 PM
Yes, if you do not have your Proxy's ACL limiting to your internal LAN, the outside world will have access to your proxy. Disabling access to port 8080 is a sure way to prevent abuse from the outside world.

Just had the same thing last week. Shut off outside access to port 8080 and the bw magically reappeared. Still see some ips from Japan and China trying, but very little traffic. Uncomment the line in the standard fw config. If your situation is different, please let us know. Don't want to miss doing something we should be doing. Thanks.