Jump to content

Recommended Posts

Posted

We have asked students to remove the app and if found there is consequences.

 

There are 4 websites I have found it visits, you can tell from the same visit to the site, untill we get Lightspeed Rocket 3 I think this is the only way.

Posted
We have asked students to remove the app and if found there is consequences.

 

There are 4 websites I have found it visits, you can tell from the same visit to the site, untill we get Lightspeed Rocket 3 I think this is the only way.

 

Which domains have you blocked? I'll check our logs. Nothing unusual stands out among the popular sites, but with our use of Google Apps, most of the top 10 are various Google sub-domains so other sites can hide a bit in the reports...

Posted

I've put these in a blocked list and assigned to the BYOD IP Range -

 

173.245.64.0/24

emiratesnbd.com

duckshield.com

108.161.187.0/24

a.ssl.fastly.net

157.56.106.0/24

173.245.84.0/24

a248.e.akamai.net

205.164.34.0/24

cloudflare.com

157.56.144.0/24

209.73.132.0/24

173.245.65.0/24

cloudflaressl.com

209.73.136.0/24

173.245.66.0/24

hawkhost.com

miisolutions.net

216.172.142.0/24

173.245.67.0/24

cloudfront.net

198.144.116.0/24

50.117.61.0/24

mozilla.org

199.255.208.0/21

50.117.72.0/24

204.14.77.0/24

paypal.com

68.68.108.0/24

emirates.com

204.14.79.0/24

get.adobe.com

209.73.137.0/24

209.73.151.0/24

212.118.232.0/24

216.172.135.0/24

216.172.138.0/24

46.16.32.0/22

46.16.36.0/22

66.171.229.0/24

68.68.107.0/24

69.22.168.0/24

69.22.170.0/24

69.22.185.0/24

74.115.0.0/21

94.245.121.0/24

 

It seems I have stopped it for now, would be great for others to try.

Posted

I have narrowed down the list -

duckshield.com

mozilla.org

emiratesnbd.com

paypal.com

emirates.com

get.adobe.com

 

It will just stick on connecting, it removes the cloudfront cdn which was breaking sites like tes.com

Posted

Also if you do a report on Lightspeed to these destinations you can see if they have tried to connect ... unlikerly to connect to Mozilla on a mobile device or emiratesnbd.com but the others just check.

 

mozilla.org

emiratesnbd.com

paypal.com

emirates.com

get.adobe.com

Posted
I have narrowed down the list -

the cloudfront cdn which was breaking sites like tes.com

 

I have blocked the top level of cloudfront CDN and then individually permitted those subdomains which are used for legit sites such as TES. I found https://www.cdnplanet.com/tools/cdnfinder/ an excellent tool for that; you give it a URL and it tells you all the domains which are used to serve up that page. Obviously you can do that by right-clicking and "view source" but this is quicker.

  • Thanks 1
  • 3 weeks later...
Posted

I just tested it again on our network and it's still blocked for us.

 

The fix that Opendium implemented has worked even after they updated their URLs. 10 Points to Mr. Hill!

  • Thanks 1
Posted
I just tested it again on our network and it's still blocked for us.

 

The fix that Opendium implemented has worked even after they updated their URLs. 10 Points to Mr. Hill!

 

Which urls are you blocking?

 

Thanks

 

James

  • 4 weeks later...
Posted
Well I cant be totally certain that it is 100% blocked. But, if I look at my M400 Application control report from yesterday it show it has blocked HotspotShield 360 times. So it looks like I have either totally blocked it or made it very had for the pupils to use it .
Posted (edited)

Just got this update from BTLS - https://education.btlancashire.co.uk/support/security-and-safeguarding.aspx

 

Risks and how you can manage them e.g. BYOD

 

Information, hints and tips around managing 'Bring Your Own Devices' in school can be found below.

 

http://www.nen.gov.uk/advice/bring-your-own-device-byod

 

Information as to how your school could implement Lightspeed SSL filtering can be found here

 

The use of Bring Your Own Device (BYOD) in schools is increasingly attractive to schools with limited resources to purchase enough devices for all pupils. It does however come with some risks that schools need to be aware of. Even with robust policies and industry recognised filtering systems in place, some schools in Lancashire have found that implementing BYOD can be challenging. In one case study in Lancashire - Bowland High - children have found ways of bypassing the filtering service using a sophisticated avoidance tool called "Hotspot Shield".

 

Hoptspot Shield is one example of VPN technologies that students have used to attempt to bypass the schools' internet filtering. It is not normally appropriate for VPN technologies to be used this way on school networks. Schools should ensure that staff and students are aware that VPN software is not allowed to be used within school. This can be accomplished by use of an acceptable use policy (AUP) with clear sanctions for any breaches.

 

On school owned and managed devices, ICT staff use effective controls such as group policy and other management tools to control the desktop and limit which applications are installed. For Bring Your own Device (BYOD) scenarios it is not possible to directly control what is installed or executed on the device (as it does not belong to the school) and this makes management of this type of filter bypass technology very challenging.

 

The Hotspot Shield VPN application is an extremely effective at disguising its traffic and evading detection. It does this by masquerading as legitimate websites and regularly changing and adding to the URLs it uses.

 

So if your school is using BYOD or is thinking of using it please be aware that there are risks. BTLS are working with Lightspeed Systems to combat these risks, but development work will take time and the target date for the firmware release to combat these avoidance tools has not yet been released by Lightspeed Systems. We will keep schools updated during 2017 of progress.

 

Nice being mentioned , just for guidence I do a report looking for traffic at these sites -

 

mozilla.org

emiratesnbd.com

emirates.com

paypal.com

turkiye.gov.tr

uludagsozluk.com

yandex.com.tr

get.adobe.com

eksisozluk.com

onedio.com

sporx.com

donanimhaber.com

 

It has to be to the extact URL so not "www.paypal.com" has to be "paypal.com", I do test with using the app myself. New URL's are added time to time, but paypal.com and get.adobe.com have been active for a while. As also use Captive Portal,so I can find who is using the app.

Edited by jhothersall
Posted

Nice being mentioned , just for guidence I do a report looking for traffic at these sites -

 

mozilla.org

emiratesnbd.com

emirates.com

paypal.com

turkiye.gov.tr

uludagsozluk.com

yandex.com.tr

get.adobe.com

eksisozluk.com

onedio.com

sporx.com

donanimhaber.com

 

I've just run that query here. A bit of traffic from various paypal subdomains, and a few instances of Mozilla and get.adobe.com from PCs not BYOD so that's probably legitimate. Other than paypal, I think I'm happy to block all of those. Even Paypal could go in the staff-only list.

Posted
All I'm seeing here is the stats.paypal.com and such like, none of the others URLs on your list. So, is this Hotspot Shield or a kid with the Paypal app on their device?
Posted
Thats not the Hotspot shield app, it will only use the direct "paypal.com"

 

Confused. Your screen shot shows api-m.paypal.com among others. That is one of the domains I'm seeing being accessed to.

Posted
That just my Paypal app on my iPhone, when you run a report with them URLS its show subdomains. It is traffic to the extact URL. But as Hotspot Shield is always changing the list I gave before might change.
Posted

I have managed to successfully block this. I just set up a URL pattern off all the suspected URL's until it stopped. I found them by using the 'Top Traffic by domain' report. We had about 250-300 students using it across the school and they where all very annoyed i've had teachers commenting on how they have been saying they where told it could never be blocked etc etc.

 

If you want the list of URL's i have blocked and confirmed the app has stopped working please PM me i don't want to publicise it as it was about 2 days work!!!

  • Thanks 1
  • 10 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...