RJohnson91 Posted November 26, 2012 Posted November 26, 2012 (edited) Hi all, This is more a informative post rather than a question or query to LGFL. For the past 2 months now I have been battling with LGFL over 'raise an issue' about our kids being able to access porn under the LGFL filtering. Now you may think that your school is completely safe, for your own piece of mind do the following test (obviously under student filtering, in an environment of which kids cant see your screen) Go to google images, and search 'computers' in the normal search an let google display the results, now click images. Once google has displayed the images type in something 15 year old boys would think of 'Girls naked'. Now at this point google will step in with THEIR filtering, not displaying the images. Now if you click sign in, at the top right, Once signed in you can remove the google filtering and watch as the NSFW images roll in. (Obviously some images wont display because of the website they are being pulled from is indeed blocked, but scroll through some pages..) Solution to the above is block the URL that google is producing when you click sign in, perfectly fine, but what about the other 2,000,000,000,000 search engines with little to no safe search filtering. We also found that going to other search engines, we could type in the word PORN, yes as blatant as PORN and with the relaxed filtering display over 900 pages of XXX images, remember that this could be done at ANY primary school / secondary under the LGFL filtering. Please do some tests for yourself. As mentioned above we have had a case open for almost 2 months now, and LGFL are chucking us round in circles. We have had the same low level support engineer for the past 2 months, and we are getting nowhere. Apparently the 'developers' are going to get involved. Hmm. So I pose to you, is this because they don’t have a clue about the problem, or is it because they know they have a major issue, and are telling this 'smaller techies' to just 'fob us off' whilst they hide??? Edited November 26, 2012 by RJohnson91 2
X-13 Posted November 26, 2012 Posted November 26, 2012 So I pose to you, is this because they don’t have a clue about the problem, or is it because they know they have a major issue, and are telling this 'smaller techies' to just 'fob us off' whilst they hide??? C: All of the above. They probably know about it, but are stumped as to what they can do to fix it. [i'm assuming something as seemingly simple as blocking the login page isn't simple in practice.]
AngryTechnician Posted November 26, 2012 Posted November 26, 2012 (edited) Basically this is because Google has for some time enabled secure search (and only secure search) for any logged in user. If your filtering does not combat Google secure search, all of Google search is available. If you control your own DNS server, you may be able to combat this locally by adding your own DNS record to resolve www.google.co.uk to nosslsearch.google.com (substitute your local country suffix as appropriate, i.e. whichever one the geographic IP detection redirects you to). Google suggest using a CNAME record, but there are issues with this on Windows servers, so you may have to resort to an A record and make sure to update it when the IP chnages (not often, but does happen). Edited November 26, 2012 by AngryTechnician
elsiegee40 Posted November 26, 2012 Posted November 26, 2012 Do your students have mandatory profiles? If you set up the mandatory profile with strict safe search on, it will at least be reset to strict every time the student logs on. It doesn't stop them turning strict safe search off, but it does help!
SYNACK Posted November 26, 2012 Posted November 26, 2012 (edited) Basically this is because Google has for some time enabled secure search (and only secure search) for any logged in user. If your filtering does not combat Google secure search, all of Google search is available. If you control your own DNS server, you may be able to combat this locally by adding your own DNS record to resolve Google to nosslsearch.google.com (substitute your local country suffix as appropriate, i.e. whichever one the geographic IP detection redirects you to). Google suggest using a CNAME record, but there are issues with this on Windows servers, so you may have to resort to an A record and make sure to update it when the IP chnages (not often, but does happen). Love the irony, the 'issues' are caused by the fact the Windows follows the standards in order to protect users from potentially malicious actions. If your using TMG you can use SSL inspection and rewrite safe search to on all the time, I think smoothwall does this too. Edited November 26, 2012 by SYNACK
chazzy2501 Posted November 26, 2012 Posted November 26, 2012 You may notice that the search filtering only applies in english (isp and google). Pupils here can type boobs, porn in spanish or french in the co.uk google and get all kinds of thing up:)
Geoff Posted November 26, 2012 Posted November 26, 2012 No filtering system is perfect, no matter what technical measures you implement to block content there is always a way around it.
chazzy2501 Posted November 26, 2012 Posted November 26, 2012 oh the most shocking website to get through our filter (and you should check it too) meatspin.com.. just block it don't go there trust me. I was shocked!
SchoolsBroadband Posted November 26, 2012 Posted November 26, 2012 Have you any idea what kind of filtering LGFL uses? I must admit that sounds pretty bad..... Many types of firewall can enforce google safesearch (and other search engines equivalent) even if the user logs in and turns it off), Fortinet, Smoothwall etc all do this. Perhaps to get around the poor filtering you should consider putting another device onsite? I know our Fortinets can work in transparent mode so you don't even have to do any network reconfigurations. Not sure about Smoothwall, best ask @TomNewton Thanks Dave
chris_uk Posted November 26, 2012 Posted November 26, 2012 Won't don't you add this to the filtering solution and select to ban them all. *.google.*/*safe=off* *.google.*/advanced_image_search* *.google.*/advanced_search* *.google.*/preferences* Yes it is over kill to do this. We use censornet and are an LGFL school. Censornet allows us to force the use of google safe search.
synaesthesia Posted November 26, 2012 Posted November 26, 2012 @SchoolsBroadband : fortinet ignores safesearch for as long as it's used in HTTPS mode. Just trying to work around it now.
AngryTechnician Posted November 26, 2012 Posted November 26, 2012 We use censornet and are an LGFL school. Censornet allows us to force the use of google safe search. Forcing Safe Search only works if your filter does HTTPS decryption. If the traffic remains encrypted, all the filter will see is the domain name, so it can't filter by anything after the / or do any content or request rewriting.
AngryTechnician Posted November 26, 2012 Posted November 26, 2012 You may notice that the search filtering only applies in english (isp and google). Pupils here can type boobs, porn in spanish or french in the co.uk google and get all kinds of thing up:) Just tried this out (purely in the name of research). Safe Search blocks 'boobs' in Spanish, while 'porn' was blocked by Smoothwall in both Spanish and French. Both Smoothwall and Safe Search did let through 'boobs' in French, but the results were still filtered and were relatively tame. I tried a few other terms in a variety of languages, and between Smoothwall and Safe Search they did a pretty good job of keeping things tame. Again, all of this can be bypassed if your filter is letting through encrypted search.
RJohnson91 Posted November 26, 2012 Author Posted November 26, 2012 (edited) Wow loads of replies! I know that each filtering has its flaws but this seems to be a little silly, I knew that not all sites would be blocked of course not, however considering the nature of the institute, being a school with young children. I thought that 'porn' wouldn't be able to slip through. But any how, I think running an on site firewall is going to be the only option, we have discussed 'smoothwall' as apparently it is quite good, as LGFL's system doesn't seem to be working. I have tried to block those google URL extensions, and to no prevail. But I have been given and assured by LGFL that a new keyword block of '/tbm=isch/' will stop the use of google images, but only google images, and they want us to ask for a re-cat when we find a new search engine. So what im going to do this weekend is type 'search engine' into google, and write down each and every one (About 1,230,000,000 results <- Actual results) and then ask for a re-cat to block every one, thats my weekend sorted... Anyone fancy joining me? As for that 'meat' website, I wont look as i dont want to 'kill the cat', l'll just block. Thanks for the heads up. Maybe we should start a post titled 'Websites to block' and everyone post URLs, get a complete list? Apparently there is one, which is good! Ryan Edited November 26, 2012 by RJohnson91
Edu-IT Posted November 26, 2012 Posted November 26, 2012 Maybe we should start a post titled 'Websites to block' and everyone post URLs, get a complete list? There's one already, do a quick search.
RJohnson91 Posted November 26, 2012 Author Posted November 26, 2012 There's one already, do a quick search. Awesome, Haven't searched yet just throwing ideas out!
sonofsanta Posted November 26, 2012 Posted November 26, 2012 Both Smoothwall and Safe Search did let through 'boobs' in French, but the results were still filtered and were relatively tame. Ze french, zey are jus' more relaxed about zese zings. [/hopelessly outdated stereotyping] 2
X-13 Posted November 26, 2012 Posted November 26, 2012 [/hopelessly outdated stereotyping] The French won't care. And, on the off chance a Frenchman takes offence, threaten them with violence. They'll surrender before you're even finished.
elsiegee40 Posted November 26, 2012 Posted November 26, 2012 Maybe we should start a post titled 'Websites to block' and everyone post URLs, get a complete list? Apparently there is one, which is good! Ryan This is it: http://www.edugeek.net/forums/internet-related-filtering-firewall/65696-one-block.html
AngryTechnician Posted November 26, 2012 Posted November 26, 2012 I have been given and assured by LGFL that a new keyword block of '/tbm=isch/' will stop the use of google images I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective.
RJohnson91 Posted November 26, 2012 Author Posted November 26, 2012 I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective. Yeah we have blocked the kids logging into google, by blocking the URL spat out when you click log in, so that should fix it, LGFL are offering nothing other than a 'Well pfft we block waht we block, you have to just deal with it' attitude so we are looking into an additional firewall.
chazzy2501 Posted November 26, 2012 Posted November 26, 2012 (edited) I know I'm sounding like a broken record, but in case you haven't guessed, this will only work if the search is not encrypted. If the user is logged in, it will be encrypted, and this keyword filter will be rendered ineffective. This is why I whitelist TLS. I only allow TLS if I've added it to my exception list. Originally I'd done this to stop proxy bypass sites. but the google encrypted fits, I'm just glad they changed the URL! btw porn and boobie is as daring as I get in edugeek, think ruder and body parts and actions in french, spanish, etc! Edited November 26, 2012 by chazzy2501
RJohnson91 Posted November 26, 2012 Author Posted November 26, 2012 Just to let people know LGFL have admitted that the key words that are listed in the ''Global and RBC Keywords'' Only apply to the following web sites: Google, Yahoo, MetaCrawler, Live Search, Excite, Lycos, AOL Search, Dog Pile, Hot Bot, Bing, Ask, YouTube. So any students can go to another search engine and type in a keyword listed and gain access to any of the images. Ryan
Nodrog Posted November 26, 2012 Posted November 26, 2012 Hi The filtering system in LGfL 2.0 is a bit on the complex side as it’s grown over the years – previous school I was at had WebScreen 1 and the LGfL system is WebScreen 2.0 when I asked this was because of the complexity of all the required solutions that people wanted and asked for have been rolled into the product so it has zillions of buttons. X13 is right just block the login page but this will not help with other Google services you might want to gain access to. Theres also a dozen of other tricks you can apply to restrict access to google and other sites like key words and such like. Best thing I did was go on a WebScreen training course at Atomwide which was free – have you done this ? if not it will help you out but to get fine control on the filter system needs careful setup on your part. The alternative is to have an aggressive filter but you then need to live with the other sites it will block – course it doesn’t help that google and all the other search engines want to let everything through anyway. Sorting via dns does work but again hampers progress in other areas. I believe in general all the filter systems suffer this feature set. Decrypting ssl – would do the trick but that’s a whole other ball game – imagine a fraud on a bank site that you have un-packed the ssl and wrapped it back up with an error in it ….. If you have a local firewall you will need to configure it so it’s worth tweaking the WebScreen II set up first before shelling out on another firewall – with another firewall I’m not convinced you will be that much better off.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now