Vulnerability Development mailing list archives

Re: N2H2 Web Proxy/Filter appliance


From: holobyte () HOLOBYTE ORG (Eric Wanner)
Date: Sat, 17 Jun 2000 01:45:41 -0700


Far from useless.  Set your routers to do policy based routing, routing
all web traffic through the proxy, set squid to accept it and bam! you've
got it covered.  The benefit of that is also that you don't have to
configure the proxy into the web browsers either.  If you don't want
to/can't do policy based routing, you have a couple other alternatives:

A) Block port 80 and 443 outbound.  Make it so they can't get to a web
site unless it's through the proxy.

B) Use an internal block of addresses.  You can't do much from there w/o a
translation server of some sort.

On the other hand, if you don't set up anything correctly, there's
probably a way to get around it ;).

--

Eric Wanner

On Fri, 16 Jun 2000, Alex Schuetz wrote:

Hi !

No , I havent heard about n2h2 , and I dont want to either. But I heard
about a free GNU software called "SQUIDGUARD". It does exactly what you
mentioned:

* Webpage redirection
* Webpage blocking (censoring) if the URL contains some strings of your
choice (regular search expressions are allowed)
* Proxying.

I tried to chat over the Web just to find out that any URL with "porn",
"sex" and "chat" was, shall we say, "disabled".

Now : Change your browser settings from "use a proxy" to "Direct
connection to the internet" and guess what? You've just disabled the
censoring proxy in three seconds. Oh, great. Amazing what simple
stupidity can do.

This makes all "proxy" solutions rather useless.

Greetings

Alex

PS: Yes I'm on an educational institution too. They really educate
hackers or something, y'know ? *sneer*

---------------------------------------------------------------



Mark wrote:

Has anyone ever heard of a company by the name of N2H2 (www.n2h2.com),
providers of a web proxy/filter appliance, suitable for education and
state requirements for content filtering?

Arguments about the issues surrounding censorship aside, especially since
we are an educational institution and have no choice, has anyone heard of
exploits against their proxy/filter appliance, or even know what kinds of
services it is running?

The PHB is doing typical PHB things and dealing only with salespeople, and
is going out on his own on this, so I really know nothing about it.  Any
help would be greatly appreciated!

thanks
mark




Current thread: