Monitoring encrypted web traffic with Squid Proxy and Splunk!

Поделиться
HTML-код
  • Опубликовано: 2 окт 2024

Комментарии • 12

  • @nagarajubalusa2598
    @nagarajubalusa2598 2 года назад +5

    Clean and clear.
    It would be great to see a complete video demonstrating how to build a Squid Proxy with SSL/TLS inspection and LDAP authentication.

    • @nagarajubalusa2598
      @nagarajubalusa2598 2 года назад +1

      @Satiex Any update on my request? It would be really great to see that complete setup.

  • @RM-gm7lu
    @RM-gm7lu 2 года назад +2

    Great Video mate! Thanks for sharing. Just setting up my lab too to test this very same thing. Cheers!

  • @lis6502
    @lis6502 2 года назад +2

    First of all i'd like to emphasize on how professional this all looks. Smal window with speaker, largest surface takes the actual subject.
    Also, i like very much is getting deep into "meat" withough unneccessary mumblink.
    what i don't like however is this annoying looped music in background. Srsly, i'd rather prefer to play my own moody blues while consuming this kind of content ;)

    • @Satiex
      @Satiex  2 месяца назад +1

      Thanks for the comment. I don't do a lot of YouTubing but I may start to release more videos shortly. The background music is mainly to drain out any humming or awkward silences which is why I kept the volume low. I think it also helps make the jump cuts in the video less noticeable because the music holds it together. A lot of videos use this technique. That said I will probably experiment with different methods if I make further videos.

    • @lis6502
      @lis6502 2 месяца назад

      @@Satiex you say "awkward silences or humming", i say "value-added ASMR", werenotthesame.jpg :P

  • @DemocracyManifest-vc5jn
    @DemocracyManifest-vc5jn Год назад

    Great stuff mate. Im wondering is there a step missing where we add squid proxy certificate to our trustore?
    We should go a step deeper and get traffic beyond tls. When an application establishes connection using something other than https

    • @Satiex
      @Satiex  2 месяца назад

      Yeah, I didn't cover adding the newly minted certificate to the browsers trust store - you will need to do this.
      I haven't explored inspecting other encrypted traffic but I am interested in checking that out.

  • @mithubopensourcelab482
    @mithubopensourcelab482 Год назад

    Great video. Can I do ssl inspection using pfsense and splunk ? Do I need a physical system to install splunk or just pfsense host is enough ?

    • @Satiex
      @Satiex  2 месяца назад

      I believe that PFSense is router software so mainly works at layer 3, where as SSL inspection happens at layer 7. Maybe you could install Squid on the same system that is running PFSense and do it that way, but I haven't explored this.

  • @maciejdawczak9893
    @maciejdawczak9893 10 месяцев назад

    Hey what about this video about building proxy?

    • @Satiex
      @Satiex  2 месяца назад +1

      Sorry I haven' been checking the comments. This was a few years ago now so I'll try and release an updated version which includes the build of the proxy.