Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 443
  • Last Modified:

Squid server - downandup virus

I have a squid proxy working with dansguardian.

My ISP sends me this notification:

>  Rete:        MYNETWORK (x.x.x.x/xx)
>  IP locale:    x.x.x.x
>
>  Data e ora:    2013-01-28 08:02:26 UTC+0
>  porta locale:    1670
>  IP remoto:    149.20.56.32:80
>  Malware:    downadup
>  HTTP request:    GET /search?q=26 HTTP/1.0
>  HTTP agent:    Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)

What can I do to solve the problem?

Thanks
0
ltpitt
Asked:
ltpitt
  • 2
1 Solution
 
arnoldCommented:
What is the problem? Is dansguardian erroneously reports a virus infected/laden response?

Or are they suggesting your webserver is infected?
0
 
ltpittAuthor Commented:
I solved the problem blocking from iptables the suggested ip
0
 
ltpittAuthor Commented:
Worked for me
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now