[Esa-l]Squid ACLs for webmail

John D. Hardin jhardin at impsec.org
Tue Jul 24 21:00:22 PDT 2001

On Tue, 24 Jul 2001, clark shishido wrote:

> We'll need to update/maintain a list of attachment fetching URLs.

Granted. Sigh.

> I just checked YahooMail and their attachment fetch URL is in the
> form:
> http://[country].[servername].mail.yahoo.com/ym/ShowLetter/[filename]?box=...MsgId...

Okay, so add:


et. al. to the executables file, and


to the webmails file.

Could someone with a yahoo mail account and squid proxy try this?

> Also, do we need to worry about html entity substitution in the
> URL or does squid take do a match on both?

Squid normalizes the URL before checking the ACL. This bit me on
making an ACL for escaped SCRIPT tags embedded in a URL a few weeks

