Solved

Squid proxy and DNS

Posted on 2012-03-30
4
908 Views
Last Modified: 2012-05-15
We have a small network enclave that has a single machine that runs a proxy server and DNS server for that enclave. This system's IP is 192.168.1.2.

Recently we have suspected that someone's machine in that enclave might be infected.  We did some research to see if their machine was going to a specific "malicious" site.

( I am blocking some information for security / privacy reasons)

First we found in the DNS logs:

bind.log.120319:19-Mar-2012 09:41:06.885 queries: info: client 192.168.1.2#41359: query: malicious-site.com IN A + (192.168.1.2)

So it looks like maybe squid made the DNS request for the user?

I checked the access log of squid and do not see any traffic to malicious-site.com.

Can someone explain to me how DNS queries work with squid?  It looks like squid is making some queries for users and letting other users make their own queries.

Is there anyway I can track down which client made that DNS request?
0
Comment
Question by:savone
4 Comments
 
LVL 30

Accepted Solution

by:
Kerem ERSOY earned 125 total points
ID: 37789871
Hi,

There's noting special about Squid using DNS query. Only since your systems internal hosts have their proxy settings they don't do the DNS lookup for HTTP protocol and pass the site to be searched to your proxy so that your proxy resolves names and make the request.

In fact your log record indicates that it was the proxy host who made a query to your DNS about the malicious-site.com (ip 192.168.1.2 and port 41359).

I checked the access log of squid and do not see any traffic to malicious-site.com.

Squid will only log any connection if the connection succeeded. It seems that you're blocking the site access over your firewall so that squid can not connect to the site and this si why you don't have anything in your log.

Since you've blocked traffic to the site the best way to check who's connecting to the site is to listen to the proxy port with tcpdump or wireshark and locate the site which makes the request through the proxy. I won't be suggesting you to restore the connection back and check your squid logs since this might put your network and systems in jeopardy.

Cheers,
K.
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 125 total points
ID: 37790938
Squid does not proxy https requests, it only allows them to pass through encrypted.  So if a user is accessing a site using SSL the user's computer will do the DNS query.
0
 
LVL 34

Assisted Solution

by:Duncan Roe
Duncan Roe earned 125 total points
ID: 37792095
You can also update your firewall rules to log failed connection attempts
0
 
LVL 13

Assisted Solution

by:Sandy
Sandy earned 125 total points
ID: 37793227
check /etc/resolv.conf and squid -z with configuration. if any specific site is needed then i prefer to go with /etc/hosts or conditional forwarding in DNS.
0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS Woes 7 50
Powershell knowledge 2 46
RRAS AND DNS 15 46
DNS spf record 14 54
I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
If you have a multi-homed DNS setup in windows, you can have issues with connectivity to the server that hosts the DNS services (or even member servers of your domain if this same DNS server is a DC). This is because windows registers all of its IPs…
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question