Jump to content

Recommended Posts

Posted (edited)

Hi all,

 

This is more a informative post rather than a question or query to LGFL.

 

For the past 2 months now I have been battling with LGFL over 'raise an issue' about our kids being able to access porn under the LGFL filtering.

 

Now you may think that your school is completely safe, for your own piece of mind do the following test (obviously under student filtering, in an environment of which kids cant see your screen)

 

Go to google images, and search 'computers' in the normal search an let google display the results, now click images. Once google has displayed the images type in something 15 year old boys would think of 'Girls naked'. Now at this point google will step in with THEIR filtering, not displaying the images. Now if you click sign in, at the top right, Once signed in you can remove the google filtering and watch as the NSFW images roll in. (Obviously some images wont display because of the website they are being pulled from is indeed blocked, but scroll through some pages..)

 

Solution to the above is block the URL that google is producing when you click sign in, perfectly fine, but what about the other 2,000,000,000,000 search engines with little to no safe search filtering.

 

We also found that going to other search engines, we could type in the word PORN, yes as blatant as PORN and with the relaxed filtering display over 900 pages of XXX images, remember that this could be done at ANY primary school / secondary under the LGFL filtering.

 

Please do some tests for yourself.

 

As mentioned above we have had a case open for almost 2 months now, and LGFL are chucking us round in circles. We have had the same low level support engineer for the past 2 months, and we are getting nowhere. Apparently the 'developers' are going to get involved. Hmm.

 

So I pose to you, is this because they don’t have a clue about the problem, or is it because they know they have a major issue, and are telling this 'smaller techies' to just 'fob us off' whilst they hide???

Edited by RJohnson91
  • Thanks 2
Posted
So I pose to you, is this because they don’t have a clue about the problem, or is it because they know they have a major issue, and are telling this 'smaller techies' to just 'fob us off' whilst they hide???

 

C: All of the above.

 

They probably know about it, but are stumped as to what they can do to fix it. [i'm assuming something as seemingly simple as blocking the login page isn't simple in practice.]

Posted (edited)

Basically this is because Google has for some time enabled secure search (and only secure search) for any logged in user. If your filtering does not combat Google secure search, all of Google search is available.

 

If you control your own DNS server, you may be able to combat this locally by adding your own DNS record to resolve www.google.co.uk to nosslsearch.google.com (substitute your local country suffix as appropriate, i.e. whichever one the geographic IP detection redirects you to). Google suggest using a CNAME record, but there are issues with this on Windows servers, so you may have to resort to an A record and make sure to update it when the IP chnages (not often, but does happen).

Edited by AngryTechnician
Posted
Do your students have mandatory profiles? If you set up the mandatory profile with strict safe search on, it will at least be reset to strict every time the student logs on. It doesn't stop them turning strict safe search off, but it does help!
Posted (edited)
Basically this is because Google has for some time enabled secure search (and only secure search) for any logged in user. If your filtering does not combat Google secure search, all of Google search is available.

 

If you control your own DNS server, you may be able to combat this locally by adding your own DNS record to resolve Google to nosslsearch.google.com (substitute your local country suffix as appropriate, i.e. whichever one the geographic IP detection redirects you to). Google suggest using a CNAME record, but there are issues with this on Windows servers, so you may have to resort to an A record and make sure to update it when the IP chnages (not often, but does happen).

 

Love the irony, the 'issues' are caused by the fact the Windows follows the standards in order to protect users from potentially malicious actions.

 

If your using TMG you can use SSL inspection and rewrite safe search to on all the time, I think smoothwall does this too.

Edited by SYNACK
Posted
You may notice that the search filtering only applies in english (isp and google). Pupils here can type boobs, porn in spanish or french in the co.uk google and get all kinds of thing up:)
Posted

Have you any idea what kind of filtering LGFL uses? I must admit that sounds pretty bad.....

 

Many types of firewall can enforce google safesearch (and other search engines equivalent) even if the user logs in and turns it off), Fortinet, Smoothwall etc all do this.

 

Perhaps to get around the poor filtering you should consider putting another device onsite? I know our Fortinets can work in transparent mode so you don't even have to do any network reconfigurations. Not sure about Smoothwall, best ask @TomNewton

 

Thanks

 

Dave

Posted

Won't don't you add this to the filtering solution and select to ban them all.

*.google.*/*safe=off*

*.google.*/advanced_image_search*

*.google.*/advanced_search*

*.google.*/preferences*

 

Yes it is over kill to do this. We use censornet and are an LGFL school. Censornet allows us to force the use of google safe search.

Posted
We use censornet and are an LGFL school. Censornet allows us to force the use of google safe search.

Forcing Safe Search only works if your filter does HTTPS decryption. If the traffic remains encrypted, all the filter will see is the domain name, so it can't filter by anything after the / or do any content or request rewriting.

Posted
You may notice that the search filtering only applies in english (isp and google). Pupils here can type boobs, porn in spanish or french in the co.uk google and get all kinds of thing up:)

 

Just tried this out (purely in the name of research).

 

Safe Search blocks 'boobs' in Spanish, while 'porn' was blocked by Smoothwall in both Spanish and French. Both Smoothwall and Safe Search did let through 'boobs' in French, but the results were still filtered and were relatively tame. I tried a few other terms in a variety of languages, and between Smoothwall and Safe Search they did a pretty good job of keeping things tame.

 

Again, all of this can be bypassed if your filter is letting through encrypted search.

Posted (edited)

Wow loads of replies!

 

I know that each filtering has its flaws but this seems to be a little silly, I knew that not all sites would be blocked of course not, however considering the nature of the institute, being a school with young children. I thought that 'porn' wouldn't be able to slip through.

 

But any how, I think running an on site firewall is going to be the only option, we have discussed 'smoothwall' as apparently it is quite good, as LGFL's system doesn't seem to be working. I have tried to block those google URL extensions, and to no prevail. But I have been given and assured by LGFL that a new keyword block of '/tbm=isch/' will stop the use of google images, but only google images, and they want us to ask for a re-cat when we find a new search engine.

 

So what im going to do this weekend is type 'search engine' into google, and write down each and every one (About 1,230,000,000 results <- Actual results) and then ask for a re-cat to block every one, thats my weekend sorted... Anyone fancy joining me?

 

As for that 'meat' website, I wont look as i dont want to 'kill the cat', l'll just block. Thanks for the heads up.

 

Maybe we should start a post titled 'Websites to block' and everyone post URLs, get a complete list? Apparently there is one, which is good!

 

Ryan

Edited by RJohnson91
Posted
Maybe we should start a post titled 'Websites to block' and everyone post URLs, get a complete list?

There's one already, do a quick search.

Posted
Both Smoothwall and Safe Search did let through 'boobs' in French, but the results were still filtered and were relatively tame.

 

Ze french, zey are jus' more relaxed about zese zings.

 

[/hopelessly outdated stereotyping]

  • Thanks 2
Posted
[/hopelessly outdated stereotyping]

 

The French won't care.

 

And, on the off chance a Frenchman takes offence, threaten them with violence. They'll surrender before you're even finished.

Posted
I have been given and assured by LGFL that a new keyword block of '/tbm=isch/' will stop the use of google images

I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective.

Posted
I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective.

 

Yeah we have blocked the kids logging into google, by blocking the URL spat out when you click log in, so that should fix it, LGFL are offering nothing other than a 'Well pfft we block waht we block, you have to just deal with it' attitude so we are looking into an additional firewall.

Posted (edited)
I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective.

 

 

This is why I whitelist TLS. I only allow TLS if I've added it to my exception list. Originally I'd done this to stop proxy bypass sites. but the google encrypted fits, I'm just glad they changed the URL!

 

 

btw porn and boobie is as daring as I get in edugeek, think ruder and body parts and actions in french, spanish, etc! ;)

Edited by chazzy2501
Posted

Just to let people know LGFL have admitted that the key words that are listed in the ''Global and RBC Keywords'' Only apply to the following web sites: Google, Yahoo, MetaCrawler, Live Search, Excite, Lycos, AOL Search, Dog Pile, Hot Bot, Bing, Ask, YouTube.

 

So any students can go to another search engine and type in a keyword listed and gain access to any of the images.

 

Ryan

Posted

Hi

 

The filtering system in LGfL 2.0 is a bit on the complex side as it’s grown over the years – previous school I was at had WebScreen 1 and the LGfL system is WebScreen 2.0 when I asked this was because of the complexity of all the required solutions that people wanted and asked for have been rolled into the product so it has zillions of buttons. X13 is right just block the login page but this will not help with other Google services you might want to gain access to. Theres also a dozen of other tricks you can apply to restrict access to google and other sites like key words and such like. Best thing I did was go on a WebScreen training course at Atomwide which was free – have you done this ? if not it will help you out but to get fine control on the filter system needs careful setup on your part. The alternative is to have an aggressive filter but you then need to live with the other sites it will block – course it doesn’t help that google and all the other search engines want to let everything through anyway. Sorting via dns does work but again hampers progress in other areas. I believe in general all the filter systems suffer this feature set. Decrypting ssl – would do the trick but that’s a whole other ball game – imagine a fraud on a bank site that you have un-packed the ssl and wrapped it back up with an error in it …..

 

If you have a local firewall you will need to configure it so it’s worth tweaking the WebScreen II set up first before shelling out on another firewall – with another firewall I’m not convinced you will be that much better off.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...