Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SquidGuard Default Blacklist SafeSearch settings and Shallalist

    Scheduled Pinned Locked Moved pfSense Packages
    39 Posts 6 Posters 40.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jsg
      last edited by

      I am highly interested by this and downloaded the file.
      But I need first to make a backup of my pfsense box to try it.

      1 Reply Last reply Reply Quote 0
      • J
        jsg
        last edited by

        Hi, I found this : http://www.safesearchlive.com/
        They have a list of search engines  (some of them is first time I hear about…)

        1 Reply Last reply Reply Quote 0
        • D
          dvserg
          last edited by

          @jsg:

          Hi, I found this : http://www.safesearchlive.com/
          They have a list of search engines  (some of them is first time I hear about…)

          Thanks

          SquidGuardDoc EN  RU Tutorial
          Localization ru_PFSense

          1 Reply Last reply Reply Quote 0
          • J
            jsg
            last edited by

            I just tried your add but I can't get it working.
            Do I only have to select the 'rewrite' to google in the default tab and tehn apply to activate Google safe search?
            Looking at the log , it looks to be enable:
            default {
            pass !in-addr !blk_BL_aggressive !blk_BL_dating !blk_BL_downloads !blk_BL_drugs !blk_BL_hacking !blk_BL_porn !blk_BL_sex_lingerie !blk_BL_spyware !blk_BL_tracker !blk_BL_violence !blk_BL_warez !blk_BL_weapons all
            redirect 301:http://192.168.1.1:8000/captiveportal-contenu.html
            rewrite safesrch_google
            log block.log
            }

            But if I put 'porn' in the search box, I am given a long choice of site. If I happen manually safe=active to the URL , this activate the safesearch thought…

            Thanks

            1 Reply Last reply Reply Quote 0
            • J
              jsg
              last edited by

              I have played a bit with the regexp string and it looks like either:

              • squidguard doesn't recognise goole string
              • squid doesn't use squidguard rewritten url

              I also found this:

              02.02.2009 12:00:45 : sg_create_config: add rewrites:
              success safesrch_google;
              error
              02.02.2009 12:00:45 : sg_create_config: add Default
              02.02.2009 12:00:45 : sg_redirector_base_url: Select redirector base url (301:http://192.168.1.1:8000/captiveportal-contenu.html)
              02.02.2009 12:00:45 : sg_reconfigure: save squidGuard config to '/usr/local/etc/squidGuard/squidGuard.conf'.
              02.02.2009 12:00:45 : squid_reconfigure: Remove old redirector options from Squid config.
              02.02.2009 12:00:45 : squid_reconfigure: Add new redirector options to Squid config.

              But I do not know what is this error and where to look for. Other blocking (website) is correctly filtered and redirected to the 301 webpage.

              1 Reply Last reply Reply Quote 0
              • D
                dvserg
                last edited by

                @jsg:

                I have played a bit with the regexp string and it looks like either:

                • squidguard doesn't recognise goole string
                • squid doesn't use squidguard rewritten url

                Pls e-mail me. i send to you new XML

                SquidGuardDoc EN  RU Tutorial
                Localization ru_PFSense

                1 Reply Last reply Reply Quote 0
                • D
                  dvserg
                  last edited by

                  Package updated. 'Safesearch' option and ACL rules hide/show added.

                  SquidGuardDoc EN  RU Tutorial
                  Localization ru_PFSense

                  1 Reply Last reply Reply Quote 0
                  • R
                    rafael.cardoso
                    last edited by

                    after update destinations don´t show in rules, just [] shows in acls,  ???

                    Respect is Everything!

                    1 Reply Last reply Reply Quote 0
                    • D
                      dvserg
                      last edited by

                      @rafael.cardoso:

                      after update destinations don´t show in rules, just [] shows in acls,  ???

                      All ACL rules hidden - click 'Destination ruleset >' string for show

                      SquidGuardDoc EN  RU Tutorial
                      Localization ru_PFSense

                      1 Reply Last reply Reply Quote 0
                      • J
                        jsg
                        last edited by

                        I tried the new package and got all request to google being redirected to page 301 until I unchecked all rule set.
                        I loaded again the Shalalist and configured it and filtering is working.
                        But , Google and other search engines filtering doesn't work.  Doing a test with yahoo , it looks the rewriting is not correct

                        See the url once I put the 'porno' word in the search box:

                        http://fr.yahoo.com/_ylt=AhltjCPx7r.4zVo89_YwgLmhVM8F;_ylv=0/SIG=1149dkbce/*-http://fr.search.yahoo.com/search?p=porno&fr=yfp-t-501&ei=UTF-8&rd=r1

                        I think your package is for platform 1.1 and I am running 1.2 (the only one available on mirrors). Would that be the problem?

                        1 Reply Last reply Reply Quote 0
                        • D
                          dvserg
                          last edited by

                          I tried the new package and got all request to google being redirected to page 301 until I unchecked all rule set.

                          Possible you block search engines in Shalalist This block all known popular engines (Yahoo/google too) - 301 report about this.

                          test
                          http://fr.search.yahoo.com/search;_ylt=A1f4cfpNMYhJEgkBc8pjAQx.?p=porn&y=Rechercher&fr=pnf-reg&rd=r1
                          get
                          Nous n'avons trouvé aucun résultat pour la recherche sur 'porn'.

                          SquidGuardDoc EN  RU Tutorial
                          Localization ru_PFSense

                          1 Reply Last reply Reply Quote 0
                          • J
                            jsg
                            last edited by

                            hmm , I did not. The only thing I did was to reinstall the package to get the latest release and it looks it made something to the destination rule set. Once I loaded again the Shalalist and set it up again, this was working back as normal.
                            I digged on squidguard/squid on the internet but there is apparently no easy way to debug / trace what is going on with the rewrite  ::). Any idea/hint ?

                            Thanks.

                            1 Reply Last reply Reply Quote 0
                            • J
                              jsg
                              last edited by

                              Interesting. I have click on your 'test' weblink and I got the following (see picture).
                              So there is clearly something wrong with my set up then…

                              yahho_safe.png
                              yahho_safe.png_thumb

                              1 Reply Last reply Reply Quote 0
                              • B
                                BobFather
                                last edited by

                                I have been out for a while.
                                Just getting back in to see what has happened.

                                dvserg,
                                Is this info still current, or do I need something else?

                                • download 'http://diskatel.narod.ru/pfSense/packages/squidguard_safesearch.zip'
                                • unpack to '/usr/local/pkg'
                                1 Reply Last reply Reply Quote 0
                                • D
                                  dvserg
                                  last edited by

                                  @BobFather:

                                  I have been out for a while.
                                  Just getting back in to see what has happened.

                                  dvserg,
                                  Is this info still current, or do I need something else?

                                  • download 'http://diskatel.narod.ru/pfSense/packages/squidguard_safesearch.zip'
                                  • unpack to '/usr/local/pkg'

                                  Not actual..

                                  Safesearch already built into the squidGuard. Reinstall you package.

                                  SquidGuardDoc EN  RU Tutorial
                                  Localization ru_PFSense

                                  1 Reply Last reply Reply Quote 0
                                  • B
                                    BobFather
                                    last edited by

                                    Reloaded the package and the safesearch rewrite option shows up.

                                    The squidguard.config file ends with:

                                    rew safesearch {
                                    s@(google../search?.q=.)@\1&safe=active@i
                                    s@(google..
                                    /images.q=.)@\1&safe=active@i
                                    s@(google../groups.q=.)@\1&safe=active@i
                                    s@(google..
                                    /news.q=.)@\1&safe=active@i
                                    s@(yandex../yandsearch?.text=.)@\1&fyandex=1@i
                                    s@(search.yahoo..
                                    /search.p=.)@\1&vm=r@i
                                    s@(search.live../.q=.)@\1&adlt=strict@i
                                    s@(search.msn..
                                    /.q=.)@\1&adlt=strict@i
                                    log block.log
                                    }

                                    acl {

                                    default {
                                    pass !blk_BL_adv !blk_BL_aggressive !blk_BL_dating !blk_BL_drugs !blk_BL_gamble !blk_BL_hacking !blk_BL_models !blk_BL_movies !blk_BL_porn !blk_BL_sex_lingerie !blk_BL_spyware !blk_BL_violence !blk_BL_warez !Porn_Filter all
                                    redirect http://192.168.2.1:81/sgerror.php?url=403…
                                    rewrite safesearch
                                    log block.log
                                    }
                                    }

                                    I then tested Google, Yahoo and MSN.
                                    Yahoo is the only one that is rewriting and actually blocking.
                                    To test this, for Google I added &safe=active, for msn I added &adlt=strict, to the URL's myslef.
                                    This worked, so not sure why the rewrite rule isn't working.

                                    If you need any more info from me let me know.   
                                    Search word I used was "porno".

                                    Thanks for all the help.
                                    Bob

                                    1 Reply Last reply Reply Quote 0
                                    • B
                                      BobFather
                                      last edited by

                                      I did some checking and possibly the:

                                      google..*/

                                      might work as:

                                      google…/

                                      Don't know how to change the Config manually or would test myself.

                                      Don't have any ideas on the MSN search.

                                      1 Reply Last reply Reply Quote 0
                                      • B
                                        BobFather
                                        last edited by

                                        dvserg,

                                        Do you know if the bug in pfSense causing it to crash when the safe search rules were put in manuelly is fixed?
                                        If it is, I will try writing the rules there to test and figure out what is going on.
                                        Just don't want to crash and reload right now.

                                        Thanks

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          dvserg
                                          last edited by

                                          @BobFather:

                                          dvserg,

                                          Do you know if the bug in pfSense causing it to crash when the safe search rules were put in manuelly is fixed?
                                          If it is, I will try writing the rules there to test and figure out what is going on.
                                          Just don't want to crash and reload right now.
                                          Thanks

                                          About bug - i sent bugreport and received info what in next version pfSense this bug will fixed.
                                          In my pfSense's safesearch work good (google/msn..)
                                          'google../' - is a regular expression, what mean 'google./'

                                          You can change /usr/local/pkg/squidguard.inc for you tests.

                                          SquidGuardDoc EN  RU Tutorial
                                          Localization ru_PFSense

                                          1 Reply Last reply Reply Quote 0
                                          • B
                                            BobFather
                                            last edited by

                                            @dvserg:

                                            @BobFather:

                                            dvserg,

                                            Do you know if the bug in pfSense causing it to crash when the safe search rules were put in manuelly is fixed?
                                            If it is, I will try writing the rules there to test and figure out what is going on.
                                            Just don't want to crash and reload right now.
                                            Thanks

                                            About bug - i sent bugreport and received info what in next version pfSense this bug will fixed.
                                            In my pfSense's safesearch work good (google/msn..)
                                            'google../' - is a regular expression, what mean 'google./'

                                            You can change /usr/local/pkg/squidguard.inc for you tests.

                                            I am not sure about the 'google…/' in place of the 'google..*/'
                                            This is just something I found searching the web for SquidGuard Safe Search ReWrite Rules.  (not specifically pfSense package).

                                            Thanks for the update on the pfSense Bug.  I will watch for the next version and update right away.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.