[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Squid proxy and DNS

Posted on 2012-03-30
4
Medium Priority
?
983 Views
Last Modified: 2012-05-15
We have a small network enclave that has a single machine that runs a proxy server and DNS server for that enclave. This system's IP is 192.168.1.2.

Recently we have suspected that someone's machine in that enclave might be infected.  We did some research to see if their machine was going to a specific "malicious" site.

( I am blocking some information for security / privacy reasons)

First we found in the DNS logs:

bind.log.120319:19-Mar-2012 09:41:06.885 queries: info: client 192.168.1.2#41359: query: malicious-site.com IN A + (192.168.1.2)

So it looks like maybe squid made the DNS request for the user?

I checked the access log of squid and do not see any traffic to malicious-site.com.

Can someone explain to me how DNS queries work with squid?  It looks like squid is making some queries for users and letting other users make their own queries.

Is there anyway I can track down which client made that DNS request?
0
Comment
Question by:savone
4 Comments
 
LVL 30

Accepted Solution

by:
Kerem ERSOY earned 375 total points
ID: 37789871
Hi,

There's noting special about Squid using DNS query. Only since your systems internal hosts have their proxy settings they don't do the DNS lookup for HTTP protocol and pass the site to be searched to your proxy so that your proxy resolves names and make the request.

In fact your log record indicates that it was the proxy host who made a query to your DNS about the malicious-site.com (ip 192.168.1.2 and port 41359).

I checked the access log of squid and do not see any traffic to malicious-site.com.

Squid will only log any connection if the connection succeeded. It seems that you're blocking the site access over your firewall so that squid can not connect to the site and this si why you don't have anything in your log.

Since you've blocked traffic to the site the best way to check who's connecting to the site is to listen to the proxy port with tcpdump or wireshark and locate the site which makes the request through the proxy. I won't be suggesting you to restore the connection back and check your squid logs since this might put your network and systems in jeopardy.

Cheers,
K.
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 375 total points
ID: 37790938
Squid does not proxy https requests, it only allows them to pass through encrypted.  So if a user is accessing a site using SSL the user's computer will do the DNS query.
0
 
LVL 35

Assisted Solution

by:Duncan Roe
Duncan Roe earned 375 total points
ID: 37792095
You can also update your firewall rules to log failed connection attempts
0
 
LVL 13

Assisted Solution

by:Sandy
Sandy earned 375 total points
ID: 37793227
check /etc/resolv.conf and squid -z with configuration. if any specific site is needed then i prefer to go with /etc/hosts or conditional forwarding in DNS.
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Most DNS problems are VERY easily troubleshot and identifiable if you can follow the steps a DNS query takes. I would like to share the step-by-step a DNS query takes from the origin to the destination. _____________________________________________…
This article explains how a domain name may be inadvertently appended to all DNS queries. This exhibits as described below. (CODE)And / Or: (CODE) Cause This issue can occur in either of these two scenarios. EITHER 1. A Primary DNS S…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…
Suggested Courses
Course of the Month19 days, 15 hours left to enroll

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question