FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Best way to block incoming connections from open http proxy

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] Best way to block incoming connections from open http proxy servers?
From: Christine Kronberg <seeker@shalla.de>
Date: Sat, 26 May 2007 12:45:58 +0200 (CEST)
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <981f07df0705250834r230d3a6bt42e8b487f75c2237@mail.gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <BBB5E2BE7794B94481346ED929C8C0AC1064C7@drevil.1pointe.local> <981f07df0705250834r230d3a6bt42e8b487f75c2237@mail.gmail.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
On Fri, 25 May 2007, Jerry Gardner wrote:
> On 5/21/07, Chris Smith <csmith@1pointe.com> wrote:
>> 
>>
>>  What's the recommended way to maintain a list of public, open http proxies
>>  and block them from making inbound connections to an http server with
>>  iptables?
>> 
>
> That's a losing battle you're never going to win.
>
> I may be in the minority here, but I strongly believe that accessing
> inappropriate material in a work or educational setting is a social problem,
> not a technical one.

   Chris was talking about _inbound_ traffic, not outbound. In his second
   post he gives a good reason for his quest. Yet, what has been said so
   far is true: You will always be behind in blocking.

   Anyway, there are some proxy lists like proxy.org/cgi_proxies.shtml.
   Or you extract the proxy/redirector part of url blacklist collections:
   http://squidguard.mesd.k12.or.us/blacklists.tgz
   http://squidguard.shalla.de/shallalist.html
   http://cri.univ-tlse1.fr/documentations/cache/squidguard_en.html#contrib

   Cheers,

   Christine Kronberg.

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>