Page 1
Page 1
Started By
Message

Has anyone ever dealt with trying to block UltraSurf?

Posted on 12/12/14 at 12:02 pm
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:02 pm
I have difficult problem to solve. I have a customer with no real infrastructure. There is no server, the laptops are brought from home and are mixed OS'es (Windows Home/Pro, OSX, etc).

The needed content filtering so I had her subscribe to OpenDNS. I block any DNS requests that are not heading to the OpenDNS servers.

There is apparently someone using UltraSurf to bypass OpenDNS. UltraSurf, from what I understand, is a proxy that uses outbound port 443.

We also got a subscription to iblocklist.com and I've added known proxies to a blocklist. The list is automatically updated every day.

I'm getting reports that UltraSurf is still working, so I don't know where to go from here.

Any ideas?
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:04 pm to
What I need is an up to date list of all the UltraSurf proxy sites, which apparently is hard to maintain.
Posted by Boudreaux35
BR
Member since Sep 2007
21517 posts
Posted on 12/12/14 at 12:05 pm to
So, you're asking for help to block non-work related surfing? From a message board that you're likely going to end up blocking?
Posted by lsu480
Downtown Scottsdale
Member since Oct 2007
92876 posts
Posted on 12/12/14 at 12:07 pm to
Can't you just email the person using it and tell them they are not allowed to?
Posted by bradwieser
Cornell Fan
Member since May 2008
10555 posts
Posted on 12/12/14 at 12:07 pm to
Let the damn employees surf the damn web as they please.
Posted by jmarto1
Houma, LA/ Las Vegas, NV
Member since Mar 2008
33971 posts
Posted on 12/12/14 at 12:12 pm to
Loss of productivity and usually leads to shite going the computers getting viruses, malware, etc.
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:14 pm to
I thought I put this on the tech board, sorry.
Posted by SG_Geaux
Beautiful St George
Member since Aug 2004
77987 posts
Posted on 12/12/14 at 12:15 pm to
I don't know how you could do this without something that does deep packet inspection, so it can go "Hey that is bound for UltraSurf, I am dropping that"
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:17 pm to
quote:

I don't know how you could do this without something that does deep packet inspection, so it can go "Hey that is bound for UltraSurf, I am dropping that"

By deep packet inspection do you mean the destination IP address?

If I had a current list of all UltraSurf proxies I could block this easily.
Posted by SG_Geaux
Beautiful St George
Member since Aug 2004
77987 posts
Posted on 12/12/14 at 12:21 pm to
quote:

If I had a current list of all UltraSurf proxies I could block this easily.




Like This ?
Posted by lsu480
Downtown Scottsdale
Member since Oct 2007
92876 posts
Posted on 12/12/14 at 12:21 pm to
I still don't see why you don't just email the person using it, and everyone else, and let them know that they are not allowed to and using it is cause for termination. It would take 30 seconds and fix the issue.
Posted by SG_Geaux
Beautiful St George
Member since Aug 2004
77987 posts
Posted on 12/12/14 at 12:23 pm to
quote:

It would take 30 seconds and fix the issue.


It would not fix the issue. Been doing this for almost 15 years.
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:42 pm to
quote:

I still don't see why you don't just email the person using it, and everyone else, and let them know that they are not allowed to and using it is cause for termination. It would take 30 seconds and fix the issue.


Because this isn't corporate and you can't fire these people.
This post was edited on 12/12/14 at 12:43 pm
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:44 pm to
quote:

Like This ?

Yeah, something like that. I wish it didn't have port numbers appended, I'd have to strip all that off. I also wish I could filter that because I block most of those outbound ports anyway, I'm pretty much concerned with 443, 80, etc. I guess I'll go through that and make my own list. I wonder how often UltraSurf is adding proxies though. With the i-blocklist site I had the url and the firewall automatically keeps the list updated.

Thanks though.
Posted by soccerfüt
Location: A Series of Tubes
Member since May 2013
65714 posts
Posted on 12/12/14 at 12:48 pm to
quote:

so I had her


Wait another week (when she's not oozing) and tell her to spend the money and get real about her IT solutions.

Just laptops people bring home and back to work? Really?
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 12:55 pm to
quote:

Wait another week (when she's not oozing) and tell her to spend the money and get real about her IT solutions.

Just laptops people bring home and back to work? Really?


Once again, this is not corporate.
Posted by Pettifogger
Capitol Hill Autonomous Zone
Member since Feb 2012
79234 posts
Posted on 12/12/14 at 2:10 pm to
quote:

Once again, this is not corporate.



What does that mean? Like retail or something?
Posted by Casty McBoozer
your mom's fat arse
Member since Sep 2005
35495 posts
Posted on 12/12/14 at 4:08 pm to
quote:

What does that mean? Like retail or something?


Like these aren't employees we're trying to lock down.

Students.
This post was edited on 12/12/14 at 4:09 pm
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram