Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Industry News > Software News

Reply
 
LinkBack Thread Tools
Old 10-10-09   #1 (permalink)
DX11 = FAIL...DX9 FTW
 
5entinel's Avatar
 
intel

Join Date: Apr 2007
Location: In a chair
Posts: 4,474
Blog Entries: 2

Rep: 269 5entinel is a proven member5entinel is a proven member5entinel is a proven member
Unique Rep: 196
Trader Rating: 0
Default [TheAge]Cisco shines light on dark corners(Dark web) of the Web

Quote:
Cisco launched software that shines light on potentially troublesome websites hidden in what the US computer security firm dubbed the "Dark Web."
Cisco IronPort Web Usage Controls promise to identify as much as 90 percent of "egregious" content that has escaped detection by business IT managers and security applications because of its stealthy nature on the Internet.


"The Dark Web is about corporate users' inability to see how workers are using the Web," Cisco product line manager Kevin Kennedy told AFP on Thursday.
http://news.theage.com.au/breaking-n...1009-gq3y.html
__________________
System: Asus EEEPC 1000H
CPU
Intel Atom N270
Memory
2GB
Hard Drive
160GB
Power Supply
n/a
OS
Windows 7 RTM

Last edited by 5entinel : 10-10-09 at 03:45 PM
5entinel is offline Overclocked Account   Reply With Quote
Old 10-10-09   #2 (permalink)
Lord of the Chicken Wings
 
VulcanDragon's Avatar
 
intel nvidia

Join Date: Aug 2004
Location: Columbus, OH
Posts: 6,471
Blog Entries: 43

FAQs Submitted: 1
Trader Rating: 1
Default

Hmm...I'm about to buy a couple of IronPort appliances, just sent the purchase documents to accounting last week.
__________________
Vulcan Dragon
Core i7 920 @ 3.7 GHz
Currently Playing: Dragon Age Origins (PC); GTA4:Lost and the Damned (X360);Portal (PC); New Super Mario Bros. Wii (Wii)
XBox Live Gamertag: Vulcan Draggon

System: Vulcan's Core i7
CPU
Core i7 920 @ 3.7 GHz
Motherboard
Asus P6T Deluxe
Memory
6GB Corsair XMS3 DDR3-1333
Graphics Card
EVGA GTX 260 (216)
Hard Drive
300GB Velociraptor C:, 2TB total
Power Supply
ThermalTake 850W
Case
Lian Li PC-6077
CPU cooling
TRUE 120
OS
Windows 7 Home Premium x64
Monitor
Gateway FHD2400
VulcanDragon is offline Overclocked Account   Reply With Quote
Old 10-10-09   #3 (permalink)
Danke schön
 
Tator Tot's Avatar
 
intel

Join Date: Jun 2008
Location: Ellisville, Missouri;U.S.
Posts: 15,530
Blog Entries: 3

Rep: 1667 Tator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a star
Unique Rep: 1042
Hardware Reviews: 1
Trader Rating: 9
Default

Hmm...I wonder how long till we see this implemented at the public school level, and then how long until it is circumvented.

though, I'd love to see how this stops proxy websites.

Such matters are always interesting as far as how well they work and how fast they are worked around.

System: Acer Laptop
CPU
Core i3 330m 2.13ghz
Motherboard
Intel HM55
Memory
2x2GB DDR3 1066
Graphics Card
Intel GMA HD
Hard Drive
320GB WD Black 7200RPM + 2TB F3EG External
Sound Card
Asus Xonar U1
Power Supply
45watt brick + 6cell L-ion battery
Case
Plastic
CPU cooling
Stock
GPU cooling
Stock
OS
Windows 7 Home Premium
Monitor
15.6" (1366 x 768) LED + 37" Sony Bravia1080p
Tator Tot is offline Overclocked Account Tator Tot's Gallery   Reply With Quote
Old 10-10-09   #4 (permalink)
Lord of the Chicken Wings
 
VulcanDragon's Avatar
 
intel nvidia

Join Date: Aug 2004
Location: Columbus, OH
Posts: 6,471
Blog Entries: 43

FAQs Submitted: 1
Trader Rating: 1
Default

Quote:
Originally Posted by Tator Tot View Post
Hmm...I wonder how long till we see this implemented at the public school level, and then how long until it is circumvented.

though, I'd love to see how this stops proxy websites.
You basically can't if they are configured correctly. The IronPort (or any other web content filter) sits between your outbound line and the internet...any and all outbound requests are examined by the device. So you can be blocked before you ever get to the proxy site in the first place, if "proxy sites" is a category that the IT administrator blocks.

And even if it is in non-blocking mode, your access to that site is logged; so a network admin doing their job could see that you are sending all of your outbound traffic to a proxy site...and what reason would you have to do that except that you're getting around the more specific rules in the device, right?

In theory, the only way to get around this stuff is if your network admin hasn't locked things down tightly. Which is often the case for internal political reasons (the boss likes Facebook), or the IT staff just isn't all that great (a scenario I might expect in some schools).
__________________
Vulcan Dragon
Core i7 920 @ 3.7 GHz
Currently Playing: Dragon Age Origins (PC); GTA4:Lost and the Damned (X360);Portal (PC); New Super Mario Bros. Wii (Wii)
XBox Live Gamertag: Vulcan Draggon

System: Vulcan's Core i7
CPU
Core i7 920 @ 3.7 GHz
Motherboard
Asus P6T Deluxe
Memory
6GB Corsair XMS3 DDR3-1333
Graphics Card
EVGA GTX 260 (216)
Hard Drive
300GB Velociraptor C:, 2TB total
Power Supply
ThermalTake 850W
Case
Lian Li PC-6077
CPU cooling
TRUE 120
OS
Windows 7 Home Premium x64
Monitor
Gateway FHD2400
VulcanDragon is offline Overclocked Account   Reply With Quote
Old 10-10-09   #5 (permalink)
Danke schön
 
Tator Tot's Avatar
 
intel

Join Date: Jun 2008
Location: Ellisville, Missouri;U.S.
Posts: 15,530
Blog Entries: 3

Rep: 1667 Tator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a star
Unique Rep: 1042
Hardware Reviews: 1
Trader Rating: 9
Default

Quote:
Originally Posted by VulcanDragon View Post
You basically can't if they are configured correctly. The IronPort (or any other web content filter) sits between your outbound line and the internet...any and all outbound requests are examined by the device. So you can be blocked before you ever get to the proxy site in the first place, if "proxy sites" is a category that the IT administrator blocks.

And even if it is in non-blocking mode, your access to that site is logged; so a network admin doing their job could see that you are sending all of your outbound traffic to a proxy site...and what reason would you have to do that except that you're getting around the more specific rules in the device, right?

In theory, the only way to get around this stuff is if your network admin hasn't locked things down tightly. Which is often the case for internal political reasons (the boss likes Facebook), or the IT staff just isn't all that great (a scenario I might expect in some schools).
This is very true. (IE the bolded part.)

But I'm not bound to thinking it's impossible to get passed this. It'd just be constant uphill battle it seems like.

Though, this is definitely some hardcore lockdown software.

System: Acer Laptop
CPU
Core i3 330m 2.13ghz
Motherboard
Intel HM55
Memory
2x2GB DDR3 1066
Graphics Card
Intel GMA HD
Hard Drive
320GB WD Black 7200RPM + 2TB F3EG External
Sound Card
Asus Xonar U1
Power Supply
45watt brick + 6cell L-ion battery
Case
Plastic
CPU cooling
Stock
GPU cooling
Stock
OS
Windows 7 Home Premium
Monitor
15.6" (1366 x 768) LED + 37" Sony Bravia1080p
Tator Tot is offline Overclocked Account Tator Tot's Gallery   Reply With Quote
Old 10-10-09   #6 (permalink)
Lord of the Chicken Wings
 
VulcanDragon's Avatar
 
intel nvidia

Join Date: Aug 2004
Location: Columbus, OH
Posts: 6,471
Blog Entries: 43

FAQs Submitted: 1
Trader Rating: 1
Default

Quote:
Originally Posted by Tator Tot View Post
But I'm not bound to thinking it's impossible to get passed this. It'd just be constant uphill battle it seems like.

Though, this is definitely some hardcore lockdown software.
Well you're right, nothing is impossible. But keep in mind, this isn't just software...these are hardware appliances. The software part can certainly be hacked, all software can be hacked. But your average web hacker isn't going to know what he's doing, he will be playing in a sandbox he's not used to. You would have to have some pretty good skills to figure out how to pick the locks, I would think...and since we're only talking about people on the inside trying to "get out" so they can "goof off" instead of working, the likelihood is probably low.
__________________
Vulcan Dragon
Core i7 920 @ 3.7 GHz
Currently Playing: Dragon Age Origins (PC); GTA4:Lost and the Damned (X360);Portal (PC); New Super Mario Bros. Wii (Wii)
XBox Live Gamertag: Vulcan Draggon

System: Vulcan's Core i7
CPU
Core i7 920 @ 3.7 GHz
Motherboard
Asus P6T Deluxe
Memory
6GB Corsair XMS3 DDR3-1333
Graphics Card
EVGA GTX 260 (216)
Hard Drive
300GB Velociraptor C:, 2TB total
Power Supply
ThermalTake 850W
Case
Lian Li PC-6077
CPU cooling
TRUE 120
OS
Windows 7 Home Premium x64
Monitor
Gateway FHD2400
VulcanDragon is offline Overclocked Account   Reply With Quote
Old 10-10-09   #7 (permalink)
Danke schön
 
Tator Tot's Avatar
 
intel

Join Date: Jun 2008
Location: Ellisville, Missouri;U.S.
Posts: 15,530
Blog Entries: 3

Rep: 1667 Tator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a starTator Tot is a star
Unique Rep: 1042
Hardware Reviews: 1
Trader Rating: 9
Default

Quote:
Originally Posted by VulcanDragon View Post
Well you're right, nothing is impossible. But keep in mind, this isn't just software...these are hardware appliances. The software part can certainly be hacked, all software can be hacked. But your average web hacker isn't going to know what he's doing, he will be playing in a sandbox he's not used to. You would have to have some pretty good skills to figure out how to pick the locks, I would think...and since we're only talking about people on the inside trying to "get out" so they can "goof off" instead of working, the likelihood is probably low.
Most definitely.

The hardware part of it is what's going to be the most interesting to see if it's cracked or they find a bypass for.

System: Acer Laptop
CPU
Core i3 330m 2.13ghz
Motherboard
Intel HM55
Memory
2x2GB DDR3 1066
Graphics Card
Intel GMA HD
Hard Drive
320GB WD Black 7200RPM + 2TB F3EG External
Sound Card
Asus Xonar U1
Power Supply
45watt brick + 6cell L-ion battery
Case
Plastic
CPU cooling
Stock
GPU cooling
Stock
OS
Windows 7 Home Premium
Monitor
15.6" (1366 x 768) LED + 37" Sony Bravia1080p
Tator Tot is offline Overclocked Account Tator Tot's Gallery   Reply With Quote
Old 10-10-09   #8 (permalink)
pita
 
Coma's Avatar
 
intel nvidia

Join Date: Jun 2007
Posts: 8,599

Rep: 578 Coma is becoming famousComa is becoming famousComa is becoming famousComa is becoming famousComa is becoming famousComa is becoming famous
Unique Rep: 412
Trader Rating: 0
Default

Quote:
Originally Posted by VulcanDragon View Post
You basically can't if they are configured correctly. The IronPort (or any other web content filter) sits between your outbound line and the internet...any and all outbound requests are examined by the device. So you can be blocked before you ever get to the proxy site in the first place, if "proxy sites" is a category that the IT administrator blocks.

And even if it is in non-blocking mode, your access to that site is logged; so a network admin doing their job could see that you are sending all of your outbound traffic to a proxy site...and what reason would you have to do that except that you're getting around the more specific rules in the device, right?

In theory, the only way to get around this stuff is if your network admin hasn't locked things down tightly. Which is often the case for internal political reasons (the boss likes Facebook), or the IT staff just isn't all that great (a scenario I might expect in some schools).
Well, a good blocking device should inspect your communication with the proxy (if it's unencrypted, and most people use unencrypted proxies) and see which sites you are accessing through it, blocking it as if it was a normal HTTP request. But I've yet to see even one that does this.

Quote:
Originally Posted by VulcanDragon View Post
Well you're right, nothing is impossible. But keep in mind, this isn't just software...these are hardware appliances. The software part can certainly be hacked, all software can be hacked. But your average web hacker isn't going to know what he's doing, he will be playing in a sandbox he's not used to. You would have to have some pretty good skills to figure out how to pick the locks, I would think...and since we're only talking about people on the inside trying to "get out" so they can "goof off" instead of working, the likelihood is probably low.
Why would ANYONE ever consider hacking this device to get past it? If you're intelligent enough, you'll just go through an encrypted proxy (SSH tunnel)... though I guess you could get found out if the IT admin isn't that stupid.

But then again, you could set up your rig so that it visits many other (unblocked) webpages regularly to obfuscate your proxy traffic.
__________________
When asking for help: state the goal, not the step.

System: Akiyama Mio
CPU
E6420 @ stock, 0.98v
Motherboard
Asus P5N-E SLI
Memory
2x1GB OCZ Platinum @ 800MHz 4-4-4-12 1T, 1.9v
Graphics Card
BFG 8800GT 512MB
Hard Drive
WD 250GB, 320GB SATA/3, 16MB Cache, Seagate 1TB
Power Supply
Corsair 520HX
Case
NZXT Apollo Black
CPU cooling
Stock
OS
Ubuntu 9.10 x86 & Win7 x86
Monitor
Asus VW222U

Last edited by Coma : 10-10-09 at 04:11 PM
Coma is offline Overclocked Account   Reply With Quote
Old 10-10-09   #9 (permalink)
Lord of the Chicken Wings
 
VulcanDragon's Avatar
 
intel nvidia

Join Date: Aug 2004
Location: Columbus, OH
Posts: 6,471
Blog Entries: 43

FAQs Submitted: 1
Trader Rating: 1
Default

Quote:
Originally Posted by Coma View Post
Why would ANYONE ever consider hacking this device to get past it? If you're intelligent enough, you'll just go through an encrypted proxy (SSH tunnel)... though I guess you could get found out if the IT admin isn't that stupid.
Exactly. All traffic is monitored, so it doesn't take a rocket scientist to identify questionable behavior. And once someone is identified, serious monitoring on that person can easily find out what he's doing. There is no way to avoid "Big Brother" at work/school if the IT guys know what they are doing and have time to do anything about it. (Those are big "if"s.)
__________________
Vulcan Dragon
Core i7 920 @ 3.7 GHz
Currently Playing: Dragon Age Origins (PC); GTA4:Lost and the Damned (X360);Portal (PC); New Super Mario Bros. Wii (Wii)
XBox Live Gamertag: Vulcan Draggon

System: Vulcan's Core i7
CPU
Core i7 920 @ 3.7 GHz
Motherboard
Asus P6T Deluxe
Memory
6GB Corsair XMS3 DDR3-1333
Graphics Card
EVGA GTX 260 (216)
Hard Drive
300GB Velociraptor C:, 2TB total
Power Supply
ThermalTake 850W
Case
Lian Li PC-6077
CPU cooling
TRUE 120
OS
Windows 7 Home Premium x64
Monitor
Gateway FHD2400
VulcanDragon is offline Overclocked Account   Reply With Quote
Old 10-10-09   #10 (permalink)
Overclocker
 
subliminally incorrect's Avatar
 
intel ati

Join Date: Oct 2006
Location: Ontario
Posts: 943

Rep: 66 subliminally incorrect is acknowledged by some
Unique Rep: 63
Trader Rating: 9
Default

beh, there are other means in the workplace to access the web and that is mobile browsing.

System: ಠ_ಠ
CPU
QX6850 3.7GHz 412MHz x9 1.4V
Motherboard
ASUS Commando
Memory
Mushkin XP2-8500 4GB
Graphics Card
Sapphire ATI HD 4890 N.E.
Hard Drive
WD Caviar 500GB x2 RAID-0
Sound Card
SB X-Fi Platinum Fatal1ty Champion Series
Power Supply
ENERMAX REVOLUTION 850W
Case
ANTEC 900
CPU cooling
Zalman CNPS9500LED
GPU cooling
stock
OS
Vista Ultimate 64-bit
Monitor
Samsung Syncmaster 2253BW Black 22" Widescreen LCD
subliminally incorrect is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 06:49 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2010 Shogun Interactive Development. Most rights reserved.
Page generated in 0.18191 seconds with 8 queries