Re: Restricting Open Proxies



IMHO,

Another way would be to restrict outgoing http connections from users
only to your Web Proxy. That way everybody would be forced to use it.
You could put access list on the firewall i.e. if your users are
separated from the Proxy server by a firewall

Another option is if you have application aware switches, which can be
configured to redirect all http traffic to the proxy.

The flip side is however, in case you need to bypass proxy for certian
web sites then you will have to create list of exceptions..

At times this may be too much...

Samir

On 19 Jun 2007 11:45:54 -0000, shailesh.rangari@xxxxxxxxx
<shailesh.rangari@xxxxxxxxx> wrote:
Hi List,


We are in the process of strengthening our Information Security Policy. As part of this initiative we want to restrict access to Open Proxies from the Corporate Network.


We are currently providing Internet Access through Symantec Web Security which also acts as a Proxy Server.


The access to Open Proxies that keep floating in the wild is bothering us because it might ultimately lead to Information Leakage. Has any one of you faced the same issue? What are the best practices for the same?


Any ideas or suggestions are most welcome.


Thanks

Shailesh.






Relevant Pages

  • Re: Somewhat complex nntp/inetd/open proxy question
    ... > out to usenet in general) from open proxies for abuse prevention reasons, ... > to listen for port 119 connections, which would be passed to a script ... > checks a host to see if it's an open proxy. ... there's any correlation between a news client and a proxy server, ...
    (comp.os.linux.security)
  • Re: Strange SMTP sessions with helo= syntax
    ... I remember we were doing this in Singapore a few years back to reach ... some of the website that were blocked by the provider's proxy, ... >>i believe they're all open proxies or spambots. ...
    (Incidents)
  • Re: Slashdots new policy
    ... HTTP proxy. ... Please close the proxy or ask your sysadmin or ISP to do so, ... because open proxies are used to spam web boards like this one. ... I post through Squid proxy ...
    (comp.os.linux.hardware)
  • Re: Slashdots new message
    ... Please close the proxy or ask your sysadmin or ISP ... because open proxies are used to spam web boards like this ... The problem with the world is stupidity. ...
    (alt.os.linux)