Re: [squid-users] ERROR: URL-rewrite

2014-09-29 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 29/09/2014 10:39 p.m., Alejandro Martinez wrote: > Hi > > I'm geting this error in cache.log > > ERROR: URL-rewrite produces invalid request: GET ERR HTTP1.0 > > This error gives me with squidGuard (1.4). > > I have tested a simple redirector in

Re: [squid-users] leaking memory in squid 3.4.8 and 3.4.7.

2014-09-29 Thread Victor Sudakov
Amos Jeffries wrote: > >>> > >>> I have tried looking at the cachemgr.cgi memory counters but > >>> they are too numerous and cryptic for me. > >> > >> Would you mind posting a copy of that mgr report? perhapse we can > >> see something unusual. > >> > > > > I am attaching two reports. The firs

Re: [squid-users] leaking memory in squid 3.4.8 and 3.4.7.

2014-09-29 Thread Victor Sudakov
> > Can you share the basic cache manager requests statistics and the up > time for the service? > (mgr:info) > > This would give us a basic idea of the load\requests needed to reproduce it. I am not Steve but in case you care to look at my statistics as well, I am attaching it. -- Victor Sud

Re: [squid-users] squid bandwidth saving optimization for specific sites

2014-09-29 Thread Eliezer Croitoru
It really depends on the site. If the site do not support caching since the content cannot be cached (dynamic) you probably cannot cache it. If the site supports cache you can try to modify the refresh_pattern to tweak couple things about the traffic. Can you share the website name? Eliezer

[squid-users] ERROR: URL-rewrite

2014-09-29 Thread Alejandro Martinez
Hi I'm geting this error in cache.log ERROR: URL-rewrite produces invalid request: GET ERR HTTP1.0 This error gives me with squidGuard (1.4). I have tested a simple redirector in php to check the new helper interface (The actual version of squid is 3.3.13), and It gives me the same message Squ

[squid-users] Digest auth DENIED/407 for notexistant user

2014-09-29 Thread Nils Hügelmann (anonymoX.net)
Hi, In squid 3.4.7, when authenticating with an inexistant user, i get only DENIED/407 replies. Instead of first 407 and then 403. config: auth_param digest program digest_file_auth /etc/passwd auth_param digest realm anonymox.net acl proxyauth_passed proxy_auth REQUIRED http_access allow prox

[squid-users] Nabble

2014-09-29 Thread geekguy
Hi there, Ever since going to this nabble forum I keep getting unsubscribed. I'm not sure why, I have had no warning nor am I aware of doing anything wrong. Can anyone please help me understand what is going on?? -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.co

Re: [squid-users] squid bandwidth saving optimization for specific sites

2014-09-29 Thread geekguy
Try my config: http://www.lawrencepingree.com/2014/08/13/optimized-squid-conf-configuration -for-squid-proxy-3-4-4/ From: Ahmd [via Squid Web Proxy Cache] [mailto:ml-node+s1019090n4667562...@n4.nabble.com] Sent: Monday, September 29, 2014 10:59 AM To: geekguy Subject: squid bandwidth saving o

[squid-users] squid bandwidth saving optimization for specific sites

2014-09-29 Thread Ahmd
Hi Guys , I have found that 60 % of my uses open about 4 common sites every day and we can say that they are visited so much. I began to think in a method to let squid to save the entire website since it has a lot of visits. Again , here I want to save bandwidth as I can since the v

Re: [squid-users] is there a way to hide squid from http://www.ip-score.com/ ??

2014-09-29 Thread Ahmd
Hi , thank you so much for reply , Just want to ask u , have u tested ur self and found that you are not detected ??? Does that directvie and the compile options below solve the issue ?? Wish to tell me ur experiment regards From: Visolve Squid [mailto:sq...@visolve.com]

Re: [squid-users] is there a way to hide squid from http://www.ip-score.com/ ??

2014-09-29 Thread Visolve Squid
Hello Team, We can inhibit X-Forwarded-For with *"header_access X-Forwarded-For deny all*" in squid configuration (*squid.conf*) file. #Add below Commands in squid conf: via off forwarded_for off follow_X_forwarded_for deny all Since need to build squid from source for these limitations to w

Re: [squid-users] is there a way to hide squid from http://www.ip-score.com/ ??

2014-09-29 Thread Ahmd
Hi , thanks for rpely , I have added the two directives u sent me , but still no luck and have been detected Here is the result from website: Proxy detect: Headers:Not detected Public proxy ports:Not detected Proxy score:1.8 (Detected) Any help ? From: Lawrence Pingree [ma

Re: [squid-users] shellshock pattern ?

2014-09-29 Thread geekguy
The best thing is to patch your bash. From: Eliezer Croitoru-2 [via Squid Web Proxy Cache] [mailto:ml-node+s1019090n4667556...@n4.nabble.com] Sent: Monday, September 29, 2014 7:33 AM To: geekguy Subject: Re: shellshock pattern ? On 09/29/2014 05:22 PM, [hidden email] wrote: > WE need to f

Re: [squid-users] shellshock pattern ?

2014-09-29 Thread Eliezer Croitoru
On 09/29/2014 05:22 PM, apmail...@free.fr wrote: WE need to filter out "() { :;};" patterns If I understand correctly, Not exactly since http uses encoding on urls. it will needed to be with percents and weird values. You will need ICAP\ECAP level of inspection to make sure nobody is bitten by

Re: [squid-users] shellshock pattern ?

2014-09-29 Thread Ralf Hildebrandt
* apmail...@free.fr : > Hi All, > > It's been a long while since I have laid my hands in squid configuration ( > good ol times ! ;-) ) > We were considering ways to filter out HTTP requests that would contain code > related to shellshock vulnerability. > Has anyone come up already with ACL's fo

Re: [squid-users] is there a way to hide squid from http://www.ip-score.com/ ??

2014-09-29 Thread Eliezer Croitoru
On 09/29/2014 06:05 PM, Ahmd wrote: Don’t u think there is any way to hide ? Any other luck ? Ahmd, I am sorry but you maybe either not understand. If you use a transparent proxy and remove any headers related to such a thing you are invisible!!! If a flash\java\html5 application is bei

[squid-users] shellshock pattern ?

2014-09-29 Thread apmailist
Hi All, It's been a long while since I have laid my hands in squid configuration ( good ol times ! ;-) ) We were considering ways to filter out HTTP requests that would contain code related to shellshock vulnerability. Has anyone come up already with ACL's for this ? WE need to filter out "()

Re: [squid-users] is there a way to hide squid from http://www.ip-score.com/ ??

2014-09-29 Thread Ahmd
Don’t u think there is any way to hide ? Any other luck ? From: Hunter Fuller [mailto:hful...@pixilic.com] Sent: Monday, September 29, 2014 9:38 AM To: Ahmd Cc: squid-users@lists.squid-cache.org Subject: Re: [squid-users] is there a way to hide squid from http://www.ip-score.com/ ??

Re: [squid-users] leaking memory in squid 3.4.8 and 3.4.7.

2014-09-29 Thread Eliezer Croitoru
Hey Steve, Can you share the basic cache manager requests statistics and the up time for the service? (mgr:info) This would give us a basic idea of the load\requests needed to reproduce it. Eliezer On 09/29/2014 12:04 PM, Steve Hill wrote: For what its worth, I'm also seeing a big memory le

Re: [squid-users] leaking memory in squid 3.4.8 and 3.4.7.

2014-09-29 Thread Steve Hill
On 28.09.14 08:34, Eliezer Croitoru wrote: Also to minimize the leak source try to share more information about your usage. Are you using SMP workers or not? What is the mem and info options in the cache manager page data? Did you tried "cache deny all" acl to minimize the source of the leak?

Re: [squid-users] leaking memory in squid 3.4.8 and 3.4.7.

2014-09-29 Thread Amos Jeffries
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 29/09/2014 8:16 p.m., Victor Sudakov wrote: > Amos Jeffries wrote: >>> >>> I have tried looking at the cachemgr.cgi memory counters but >>> they are too numerous and cryptic for me. >> >> Would you mind posting a copy of that mgr report? perhapse