+ Post New Thread
Results 1 to 8 of 8
Networks Thread, Proxy bypass sites regex in Technical; Hi everyone Recently noticed a lot of attempts by students on the old web-based proxy scripts. Worked out a couple ...
  1. #1

    webman's Avatar
    Join Date
    Nov 2005
    Location
    North East England
    Posts
    8,284
    Blog Entries
    2
    Thank Post
    598
    Thanked 879 Times in 617 Posts
    Rep Power
    287

    Proxy bypass sites regex

    Hi everyone

    Recently noticed a lot of attempts by students on the old web-based proxy scripts. Worked out a couple of regexes to match a some common URL formats. They work fine on our IPCop + URLFilter box. Exmaples:

    Code:
    \.(cgi|pl)/([01]+)([A-Z]{1})/)
    Example: http://judahjohnson.com/index.pl/010...2s696q672s6r6s

    Code:
    (index|browse|index2)\.php\?(q|u)=
    Example: http://whackyourlecturer.com/browse....lvdXR1YmUuY29t

    Full list Updated 22/07/2008

    Code:
    \?(q|u)=(.*)&hl=([A-Za-z0-9]{3,})
    \.php/(.*)/b([0-9]{2,})/
    \.php\?rob=(.*)&hl=([A-Za-z0-9]{3})
    \.(cgi|pl)/([01]+)([A-Z]{1})/)
    \.php/([01A-Z]+)/([A-Za-z0-9]+)
    \.php/(.*)/0/go.php$
    (index|browse|index2)\.php\?(q|u)=
    Last edited by webman; 22nd July 2008 at 09:49 AM.

  2. IDG Tech News

  3. #2


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    3,743
    Thank Post
    661
    Thanked 639 Times in 493 Posts
    Rep Power
    154
    you might find that those rules overblock slightly - certainly for CGI proxy you can be a bit less aggressive in your blocking and still be effective.

  4. #3

    bossman's Avatar
    Join Date
    Nov 2005
    Location
    North East England
    Posts
    3,313
    Thank Post
    859
    Thanked 823 Times in 597 Posts
    Rep Power
    276
    Would rather overblock than underblock we can always add to white list any site that needs unfiltering. It works and damn well the little bu**ers can't bypass the proxy now. Our ISP have still not managed to sort it out yet!!!

    BTW Tom how would you have done it?

  5. #4
    Sylv3r's Avatar
    Join Date
    Jul 2005
    Location
    Co. Durham
    Posts
    2,784
    Thank Post
    340
    Thanked 295 Times in 260 Posts
    Rep Power
    111
    Quote Originally Posted by bossman View Post
    Our ISP have still not managed to sort it out yet!!!
    Give them time

  6. #5

    webman's Avatar
    Join Date
    Nov 2005
    Location
    North East England
    Posts
    8,284
    Blog Entries
    2
    Thank Post
    598
    Thanked 879 Times in 617 Posts
    Rep Power
    287
    Quote Originally Posted by Sylv3r View Post
    Give them time
    How long should we give them... decades or millennia?

  7. #6
    Sylv3r's Avatar
    Join Date
    Jul 2005
    Location
    Co. Durham
    Posts
    2,784
    Thank Post
    340
    Thanked 295 Times in 260 Posts
    Rep Power
    111
    Quote Originally Posted by webman View Post
    How long should we give them... decades or millennia?
    We wanted some ports open last week, when we rang up today to chase them the person had closed the job ticket.

    Ports are still not open, but unfortunately now he is now on his holidays so we have to wait for him coming back before the job will get done! It could only happen to us that the "Port Opener" is unavailable as he is on his sun lounger in Spain!

    So something as "difficult" as web filtering.....

  8. #7

    webman's Avatar
    Join Date
    Nov 2005
    Location
    North East England
    Posts
    8,284
    Blog Entries
    2
    Thank Post
    598
    Thanked 879 Times in 617 Posts
    Rep Power
    287
    Quote Originally Posted by Sylv3r View Post
    We wanted some ports open last week, when we rang up today to chase them the person had closed the job ticket.

    Ports are still not open, but unfortunately now he is now on his holidays so we have to wait for him coming back before the job will get done! It could only happen to us that the "Port Opener" is unavailable as he is on his sun lounger in Spain!

    So something as "difficult" as web filtering.....
    Same thing happened to us! A little over 2 weeks by the time it was finally open. Surely somebody else there can open a port? It's not rocket science. Even better would be to give us basic access to the boxes but that seems to be asking too much

    Good luck with your ports

  9. #8


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    3,743
    Thank Post
    661
    Thanked 639 Times in 493 Posts
    Rep Power
    154
    bossman: I would have just asked for "more" 0101 etc. - it is pretty much always the same length, i'd definitely look for 3 consecutive [01]
    PHProxy is hard to do via URL only - we do much more in-page on that one. I remember one specific occasion finding a rule accidentally blocked nhs.net which was targetted at phproxy.

    I suppose overblocking is far more of a concern for me - if we overblock, it happens to hundreds of thousands of users and I can't guarantee whats in the whitelist!

SHARE:
+ Post New Thread

Similar Threads

  1. proxy bypass sites
    By bishopsgarthstockton in forum Links
    Replies: 77
    Last Post: 7th December 2006, 12:29 PM
  2. Proxy Bypass Websites
    By ticker in forum Windows
    Replies: 13
    Last Post: 24th May 2006, 09:28 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •