• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 447
  • Last Modified:

Squid server - downandup virus

I have a squid proxy working with dansguardian.

My ISP sends me this notification:

>  Rete:        MYNETWORK (x.x.x.x/xx)
>  IP locale:    x.x.x.x
>
>  Data e ora:    2013-01-28 08:02:26 UTC+0
>  porta locale:    1670
>  IP remoto:    149.20.56.32:80
>  Malware:    downadup
>  HTTP request:    GET /search?q=26 HTTP/1.0
>  HTTP agent:    Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)

What can I do to solve the problem?

Thanks
0
ltpitt
Asked:
ltpitt
  • 2
1 Solution
 
arnoldCommented:
What is the problem? Is dansguardian erroneously reports a virus infected/laden response?

Or are they suggesting your webserver is infected?
0
 
ltpittAuthor Commented:
I solved the problem blocking from iptables the suggested ip
0
 
ltpittAuthor Commented:
Worked for me
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now