Re: [squid-users] a specific host generates a 503 ...

2021-03-15 Thread Matus UHLAR - fantomas
On 12/03/21 1:14 am, Eliezer Croitoru wrote: It's sitting behind:  DDoS protection by Cloudflare So it makes sense that you would not be able to download it using wget. The only option probably is using a web browser. I would suggest contacting clamav.net web/system admins to verify what are the

Re: [squid-users] Squid 5 does not send ICAP request

2021-03-15 Thread Eliezer Croitoru
Hey Alex and Amos. These bugs are open since forever. There is a simple way to re-produce it. There is also a simple bypass to the issue but still. However, Would it be possible to fix it for 6? It doesn't to even require a single http request to test and verify. The ICAP hosts doesn't resolve for

Re: [squid-users] Protecting squid

2021-03-15 Thread Eliezer Croitoru
Hey Ben, Since you probably doesn’t have 100k users and there for passwords it wouldn't do a thing. Nobody will feel you dropping the TTL. The content of the credentials file will be in RAM so you should give it a try first and ask later. All The Bests, Eliezer Eliezer Croitoru Tech Suppo

Re: [squid-users] Protecting squid

2021-03-15 Thread Amos Jeffries
On 15/03/21 2:26 am, Ben Goz wrote: Can I configure squid authentication TTL per only source IP and ignores other parameters so authentication will be requested only once in TTL for all the sessions? Not with just authentication. You will need to use a slightly more complicated system inv

Re: [squid-users] Squid 5 does not send ICAP request

2021-03-15 Thread Alex Rousskov
On 3/15/21 5:18 AM, Eliezer Croitoru wrote: > These bugs are open since forever. > There is a simple way to re-produce it. > There is also a simple bypass to the issue but still. > However, Would it be possible to fix it for 6? Yes, it would be! We are waiting for a volunteer to contribute a qual

[squid-users] Solarwinds Information

2021-03-15 Thread rsa.sro.csse
Hi, is there any available information regarding the Solarwinds vulnerability on the Squid site? Thank you, Brian RSA - Security and Risk Office ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid

Re: [squid-users] Solarwinds Information

2021-03-15 Thread Alex Rousskov
On 3/15/21 12:49 PM, rsa.sro.c...@rsa.com wrote: > Hi, is there any available information regarding the Solarwinds > vulnerability on the Squid site? AFAICT, Squid is unaffected by (and unrelated to) CVE-2020-14005 and CVE-2020-13169, so I would not expect the Squid site to mention those CVEs. If

Re: [squid-users] a specific host generates a 503 ...

2021-03-15 Thread Walter H.
On 15.03.2021 10:14, Matus UHLAR - fantomas wrote: On 12/03/21 1:14 am, Eliezer Croitoru wrote: It's sitting behind:  DDoS protection by Cloudflare So it makes sense that you would not be able to download it using wget. The only option probably is using a web browser. I would suggest contactin