• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

ByPassing Captive Portal With Proxy

Scheduled Pinned Locked Moved Captive Portal
7 Posts 4 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tux
    last edited by Feb 15, 2015, 1:41 PM

    I can't believe that the captive portal is so easy to by pass through the squid proxy.  Is there anyway we can prevention method to such attempt?
    Here is a demo: https://www.youtube.com/watch?v=71XMJ6DqpcE

    1 Reply Last reply Reply Quote 0
    • G
      Gertjan
      last edited by Feb 15, 2015, 4:15 PM

      Euh  :)

      Squid listing on an accessible non 'local' IP on LAN ?
      Portal running on LAN instead a dedicated OPTx ?

      This video shows that stupid network admin exists  (lousy setup, etc)…. Well, that is not new ....

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • N
        Nachtfalke
        last edited by Feb 15, 2015, 10:15 PM

        @tux:

        I can't believe that the captive portal is so easy to by pass through the squid proxy.  Is there anyway we can prevention method to such attempt?
        Here is a demo: https://www.youtube.com/watch?v=71XMJ6DqpcE

        Just enable the checkbox on squid GUI which says:

        Enable this option to force captive portal to non transparent proxy users.
        NOTE: You may need to reapply captive portal config after changing this option.

        1 Reply Last reply Reply Quote 0
        • T
          tux
          last edited by Feb 16, 2015, 7:09 AM

          @Gertjan Can you enlighten me/us more?

          1 Reply Last reply Reply Quote 0
          • G
            Gertjan
            last edited by Feb 16, 2015, 9:38 AM

            Well …

            The video shows a possibility to access the proxy directly, (port 3182). That doesn't seem normal to me. Even port "22" is 'open' On a portal interface ??? => No way .... that's not a sesious setup.

            The video shows a pfSense version 1.2.3 - that like says: "Windows has a bug, and demonstrating a XP issue from back then ... " - same thing for the SQUID version used ...

            The video shows a portal install on LAN, or, I'm convinced is always better to use a separate OPTx interface.

            You saw what Nachtfalke said ? I'm not using squid, but it seems clear to me that its all about a "admin setup error".

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • J
              jahonix
              last edited by Feb 16, 2015, 12:21 PM

              @tux:

              I can't believe that the captive portal is so easy to by pass through the squid proxy.  Is there anyway we can prevention method to such attempt?

              Yes, get your network setup right.
              Use an additional interface exclusively for your captive portal users. The rest has been said already.

              1 Reply Last reply Reply Quote 0
              • T
                tux
                last edited by Feb 16, 2015, 1:13 PM

                Thanks @Gertjan for that.  I'm actually using the stable version of squid.  I think squid3 beta is the best option for me now though I would prefer the stable version.  I actually need captive portal users to use the proxy server which we heavily do caching.  Thank you everyone!

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received