Re: [squid-users] Re: dialer downloads bypassing squid acls

From: Luis Miguel R. <luism@dont-contact.us>
Date: Fri, 16 Jul 2004 21:44:01 +0200

El viernes, 16 julio del 2004 a las 02:25:00, Scott Phalen escribió:
> Something like dansguardian might do the trick.
>

This is a response from Henrik Nordstrom on a previous mail message:

-
"Are there any way to pass this downloads to the redirector?"
  
"It is already, but as you noticed there is no way for the redirector to
tell that this is a download. This is because redirectors is called on the
request before it is forwarded, and to know the returned mime type the
request must have been forwarded and the response from the web server seen
by Squid."
-

So a redirector cant be used to block this downloads.

> >If you could do regex based on the MIME filename field or the whole mime
> replied header, then you can filter something like >"filename=.*\.exe"
> stopping all .exe downloads, but you cant.
>
> > >You have the MIME type from the logs you showed us
> > >(application/octet-stream) - just block that using rep_mime_type and
> > >http_reply_access except for certain whitelisted sites.
> > >
>
> >>If you block all "application/octet-stream", you destroy the users webs
> acces blocking all kind of files, for example many swf >>(flash) and css
> files are download as "application/octet-stream".
Received on Fri Jul 16 2004 - 13:44:01 MDT

This archive was generated by hypermail pre-2.1.9 : Sun Aug 01 2004 - 12:00:02 MDT