Well, they'll use port 80 if it's availble, so you'd have to block all ports, force transparent proxy, and edit the SQUID defaults file and setup ACL's to block those sites.
Maybe the Surf Protection already has this feature.
Also, in 5.0, you might be able to do this with the IPS.