<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NetSentron &#187; Information</title>
	<atom:link href="http://www.netsentron.com/category/information/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netsentron.com</link>
	<description>Securing All the Bits.</description>
	<lastBuildDate>Fri, 15 Apr 2011 15:59:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Block Facebook</title>
		<link>http://www.netsentron.com/block-facebook/</link>
		<comments>http://www.netsentron.com/block-facebook/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 17:30:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[block facebook]]></category>

		<guid isPermaLink="false">http://www.netsentron.com/block-facebook/</guid>
		<description><![CDATA[There is lots of news about Facebook. Everything from how it generated new sales and leads to the amount of time people waste at work and how it one of the latest tools for school bullies.
A recent posting on baseline magazine will give you some of the recent facebook numbers as it relates to business.
The [...]]]></description>
			<content:encoded><![CDATA[<p>There is lots of news about Facebook. Everything from how it generated new sales and leads to the amount of time people waste at work and how it one of the latest tools for school bullies.</p>
<p>A recent posting on baseline magazine will give you some of the recent facebook numbers as it relates to business.<br />
The link to the article is here:</p>
<p><a href="http://www.baselinemag.com/c/a/Business-Intelligence/30-Fast-Facts-on-Facebook-at-Work-406941/?kc=EWWHNEMNL09132010STR1">http://www.baselinemag.com/c/a/Business-Intelligence/30-Fast-Facts-on-Facebook-at-Work-406941/?kc=EWWHNEMNL09132010STR1</a></p>
<p>We are not here to debate the merits of facebook; however, if you need to block it, I have included the instructions on how to block it using the NetSentron below. If you need a teacher, marketing department or the HR department to have access to facebook, while closing it to the rest of your network you would exempt that person or workstation from the filter.</p>
<p>The specific instructions on how to block facebook came from the following request:</p>
<p>The kids have discovered that if they go to https://www.facebook.com they can<br />
bypasss the filter. From that point on even http://www.facebook.com and<br />
facebook.ca is accessible. I need your help to block this.</p>
<p>First thing to do to block facebook is to blacklist the domains.<br />
That would include facebook.com and facebook.ca.<br />
That alone is not enough since kids will do all of the following:<br />
1) Try a proxy server &#8211; they would go to another server that is not in the black list and then facebook from the proxy server.<br />
The solution here is to block all the proxy servers. Netsentron administrators know how to do that.  There is a checkbox to block all known proxy servers.</p>
<p>2) They could go to another facebook site. The students could try facebook in Germany or France or??.<br />
Now we have to block all facebook domains.<br />
Latest exploit the kids discovered to bypass the NetSentron filter:<br />
Go to babelfish.yahoo.com enter in www.facebook.com and choose Greek to English,<br />
voila you have access to facebook even though it is blocked.<br />
The fix:<br />
Go to Filters-&gt;Content Filter<br />
Then click on &#8220;Edit Banned URL Expressions&#8221;<br />
Scroll down the window to the very bottom (you should probably see #(proxy) as the last<br />
line)<br />
Add the following line<br />
(facebook)<br />
Click on &#8220;Update Banned URL Expressions&#8221;<br />
Now, anytime that facebook shows up in the URL (which it does when you do a<br />
translation on yahoo), the site should be blocked. This works even if YAHOO.COM is in<br />
the exception list.</p>
<p>3) The students in the above case used https.  It is a secure connection (like online banking) where we should not break into the middle of the online conversation. One way to fix that is to take control the proxy server.   If we break into the middle it basically creates a &#8216;man in the middle attack&#8217;. We don&#8217;t want to look like a hacker &#8211; our job is to stop them!</p>
<p>The quick way to stop all traffic to facebook servers is to stop at the source. The final resolution was generated by Darren in our office:</p>
<p>Go to Firewall-&gt;IP Block</p>
<p>Add the two following entries:</p>
<p>TCP 69.63.176.0/20 1:65535 DROP BOTH<br />
TCP 66.220.144.0/20 1:65535 DROP BOTH</p>
<p>This will block all current IP&#8217;s owned by Facebook.</p>
<p>Darren</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsentron.com/block-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shut down the NetSentron Bypass</title>
		<link>http://www.netsentron.com/shut-down-the-netsentron-bypass/</link>
		<comments>http://www.netsentron.com/shut-down-the-netsentron-bypass/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 19:46:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Information]]></category>

		<guid isPermaLink="false">http://www.netsentron.com/?p=2237</guid>
		<description><![CDATA[This allows anyone anywhere to bypass their content filter since the traffic in now through a VPN (A safe and secure tunnel).
This is part of an internal post by Darren Crithley to the KDI techinican support team which I think if of real value to general public.
The kids at one of the schools are circumventing [...]]]></description>
			<content:encoded><![CDATA[<p>This allows anyone anywhere to bypass their content filter since the traffic in now through a VPN (A safe and secure tunnel).</p>
<p>This is part of an internal post by Darren Crithley to the KDI techinican support team which I think if of real value to general public.</p>
<p>The kids at one of the schools are circumventing the NetSentron using this:<br />
<a href="http://www.hotspotshield.com/">http://www.hotspotshield.com/</a></p>
<p>It is an installable program that becomes a proxy on their own PC and allows them to get past the NetSentron.</p>
<p>It is actually a VPN endpoint with a proxy that runs on your localhost (127.0.0.1)</p>
<p>It is using OpenVPN as a VPN client and they have set up some websites that are the endpoints. So far 68.68.108.3 and 68.68.108.4</p>
<p>There have been a lot of these VPN bypasses showing up of late and this one is pretty slick.</p>
<p>But I am able to block it, so here are the instructions for you to block it:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Go to Firewall-&gt;IP Block<br />
Choose Protocol:udp<br />
Source IP or network: 68.68.108.0/24<br />
port: *<br />
Drop Packet<br />
Direction: In and Out bound packets<br />
Enabled (yes)</p>
<p>Do the same for TCP<br />
Choose Protocol:tcp<br />
Source IP or network: 68.68.108.0/24<br />
port: *<br />
Drop Packet<br />
Direction: In and Out bound packets<br />
Enabled (yes)</p>
<p>I have probably blocked off more than I should have with the /24, but I figured that they may have a block of IP&#8217;s. You can try just the 68.68.108.3 and 68.68.108.4 (udp/tcp)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Now here is the tech part on how to figure this out if the kids are using a different product to bypass:</p>
<p>These bypasses are VPN&#8217;s and therefore they need to connect to &#8220;somewhere&#8221; so they can surf the net. That &#8220;somewhere&#8221; is what we will block.</p>
<p>If someone is not already using the bypass product, then install it on your laptop or computer.</p>
<p>Next, run it and connect to what should be a banned site.</p>
<p>Then look at the connections analysis on the NetSentron, I suspect you will see a connection to a weird port (either tcp or udp)</p>
<p>Stop the bypass product on the PC or laptop</p>
<p>Add the IP address and ALL ports to IP Block, set in and out packets.</p>
<p>Run bypass product again and see what shows up.</p>
<p>Keep doing this until you get all the IP&#8217;s</p>
<p>This hotspot shield was pretty slick, when I blocked all the UDP ports for it, it switched over to TCP and connected again. Once I had the tcp and udp blocked, that was the end of it (until they get another block of ip addresses)</p>
<p>Darren</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsentron.com/shut-down-the-netsentron-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

