jhothersall Posted March 27, 2017 Posted March 27, 2017 We have asked students to remove the app and if found there is consequences. There are 4 websites I have found it visits, you can tell from the same visit to the site, untill we get Lightspeed Rocket 3 I think this is the only way.
enjay Posted March 27, 2017 Posted March 27, 2017 We have asked students to remove the app and if found there is consequences. There are 4 websites I have found it visits, you can tell from the same visit to the site, untill we get Lightspeed Rocket 3 I think this is the only way. Which domains have you blocked? I'll check our logs. Nothing unusual stands out among the popular sites, but with our use of Google Apps, most of the top 10 are various Google sub-domains so other sites can hide a bit in the reports...
jhothersall Posted March 27, 2017 Posted March 27, 2017 I've put these in a blocked list and assigned to the BYOD IP Range - 173.245.64.0/24 emiratesnbd.com duckshield.com 108.161.187.0/24 a.ssl.fastly.net 157.56.106.0/24 173.245.84.0/24 a248.e.akamai.net 205.164.34.0/24 cloudflare.com 157.56.144.0/24 209.73.132.0/24 173.245.65.0/24 cloudflaressl.com 209.73.136.0/24 173.245.66.0/24 hawkhost.com miisolutions.net 216.172.142.0/24 173.245.67.0/24 cloudfront.net 198.144.116.0/24 50.117.61.0/24 mozilla.org 199.255.208.0/21 50.117.72.0/24 204.14.77.0/24 paypal.com 68.68.108.0/24 emirates.com 204.14.79.0/24 get.adobe.com 209.73.137.0/24 209.73.151.0/24 212.118.232.0/24 216.172.135.0/24 216.172.138.0/24 46.16.32.0/22 46.16.36.0/22 66.171.229.0/24 68.68.107.0/24 69.22.168.0/24 69.22.170.0/24 69.22.185.0/24 74.115.0.0/21 94.245.121.0/24 It seems I have stopped it for now, would be great for others to try.
jhothersall Posted March 30, 2017 Posted March 30, 2017 I have narrowed down the list - duckshield.com mozilla.org emiratesnbd.com paypal.com emirates.com get.adobe.com It will just stick on connecting, it removes the cloudfront cdn which was breaking sites like tes.com
jhothersall Posted March 30, 2017 Posted March 30, 2017 Also if you do a report on Lightspeed to these destinations you can see if they have tried to connect ... unlikerly to connect to Mozilla on a mobile device or emiratesnbd.com but the others just check. mozilla.org emiratesnbd.com paypal.com emirates.com get.adobe.com
enjay Posted March 30, 2017 Posted March 30, 2017 I have narrowed down the list - the cloudfront cdn which was breaking sites like tes.com I have blocked the top level of cloudfront CDN and then individually permitted those subdomains which are used for legit sites such as TES. I found https://www.cdnplanet.com/tools/cdnfinder/ an excellent tool for that; you give it a URL and it tells you all the domains which are used to serve up that page. Obviously you can do that by right-clicking and "view source" but this is quicker. 1
jhothersall Posted April 18, 2017 Posted April 18, 2017 How have you done this? Come back today and Hotspot shield's URLS it connects to have been updated...
w00dy01 Posted April 18, 2017 Posted April 18, 2017 I just tested it again on our network and it's still blocked for us. The fix that Opendium implemented has worked even after they updated their URLs. 10 Points to Mr. Hill! 1
jhothersall Posted April 18, 2017 Posted April 18, 2017 I just tested it again on our network and it's still blocked for us. The fix that Opendium implemented has worked even after they updated their URLs. 10 Points to Mr. Hill! Which urls are you blocking? Thanks James
w00dy01 Posted April 18, 2017 Posted April 18, 2017 Opendium have made a blog post about hotspotshield VPN here - https://www.opendium.com/node/87
deano3693 Posted May 15, 2017 Posted May 15, 2017 Has anyone managed to block this completely apart from those using Opendium? How much is this out of curiosity?
mcolbourn Posted May 16, 2017 Posted May 16, 2017 Well I cant be totally certain that it is 100% blocked. But, if I look at my M400 Application control report from yesterday it show it has blocked HotspotShield 360 times. So it looks like I have either totally blocked it or made it very had for the pupils to use it .
jhothersall Posted May 23, 2017 Posted May 23, 2017 (edited) Just got this update from BTLS - https://education.btlancashire.co.uk/support/security-and-safeguarding.aspx Risks and how you can manage them e.g. BYOD Information, hints and tips around managing 'Bring Your Own Devices' in school can be found below. http://www.nen.gov.uk/advice/bring-your-own-device-byod Information as to how your school could implement Lightspeed SSL filtering can be found here The use of Bring Your Own Device (BYOD) in schools is increasingly attractive to schools with limited resources to purchase enough devices for all pupils. It does however come with some risks that schools need to be aware of. Even with robust policies and industry recognised filtering systems in place, some schools in Lancashire have found that implementing BYOD can be challenging. In one case study in Lancashire - Bowland High - children have found ways of bypassing the filtering service using a sophisticated avoidance tool called "Hotspot Shield". Hoptspot Shield is one example of VPN technologies that students have used to attempt to bypass the schools' internet filtering. It is not normally appropriate for VPN technologies to be used this way on school networks. Schools should ensure that staff and students are aware that VPN software is not allowed to be used within school. This can be accomplished by use of an acceptable use policy (AUP) with clear sanctions for any breaches. On school owned and managed devices, ICT staff use effective controls such as group policy and other management tools to control the desktop and limit which applications are installed. For Bring Your own Device (BYOD) scenarios it is not possible to directly control what is installed or executed on the device (as it does not belong to the school) and this makes management of this type of filter bypass technology very challenging. The Hotspot Shield VPN application is an extremely effective at disguising its traffic and evading detection. It does this by masquerading as legitimate websites and regularly changing and adding to the URLs it uses. So if your school is using BYOD or is thinking of using it please be aware that there are risks. BTLS are working with Lightspeed Systems to combat these risks, but development work will take time and the target date for the firmware release to combat these avoidance tools has not yet been released by Lightspeed Systems. We will keep schools updated during 2017 of progress. Nice being mentioned , just for guidence I do a report looking for traffic at these sites - mozilla.org emiratesnbd.com emirates.com paypal.com turkiye.gov.tr uludagsozluk.com yandex.com.tr get.adobe.com eksisozluk.com onedio.com sporx.com donanimhaber.com It has to be to the extact URL so not "www.paypal.com" has to be "paypal.com", I do test with using the app myself. New URL's are added time to time, but paypal.com and get.adobe.com have been active for a while. As also use Captive Portal,so I can find who is using the app. Edited May 23, 2017 by jhothersall
enjay Posted May 23, 2017 Posted May 23, 2017 Nice being mentioned , just for guidence I do a report looking for traffic at these sites - mozilla.org emiratesnbd.com emirates.com paypal.com turkiye.gov.tr uludagsozluk.com yandex.com.tr get.adobe.com eksisozluk.com onedio.com sporx.com donanimhaber.com I've just run that query here. A bit of traffic from various paypal subdomains, and a few instances of Mozilla and get.adobe.com from PCs not BYOD so that's probably legitimate. Other than paypal, I think I'm happy to block all of those. Even Paypal could go in the staff-only list.
jhothersall Posted May 23, 2017 Posted May 23, 2017 I find that Hotspot shield goes to directly them ULRs not sub domains. Attached is a screenshot of the kinda a traffic you get from Hotspot Shield.
enjay Posted May 23, 2017 Posted May 23, 2017 All I'm seeing here is the stats.paypal.com and such like, none of the others URLs on your list. So, is this Hotspot Shield or a kid with the Paypal app on their device?
jhothersall Posted May 23, 2017 Posted May 23, 2017 Thats not the Hotspot shield app, it will only use the direct "paypal.com"
enjay Posted May 23, 2017 Posted May 23, 2017 Thats not the Hotspot shield app, it will only use the direct "paypal.com" Confused. Your screen shot shows api-m.paypal.com among others. That is one of the domains I'm seeing being accessed to.
jhothersall Posted May 23, 2017 Posted May 23, 2017 That just my Paypal app on my iPhone, when you run a report with them URLS its show subdomains. It is traffic to the extact URL. But as Hotspot Shield is always changing the list I gave before might change.
enjay Posted May 23, 2017 Posted May 23, 2017 So, one of our students has the Payal app on his phone, but not Hotspot Shield? I can cope with that...
jhothersall Posted May 23, 2017 Posted May 23, 2017 If you want send me and PM and I can call you, it is hardwork done loads of research into it.
mavhc Posted May 23, 2017 Posted May 23, 2017 Wouldn't having the filter check the ip, dns, and cert matched stop them using fake certs?
deano3693 Posted May 23, 2017 Posted May 23, 2017 I have managed to successfully block this. I just set up a URL pattern off all the suspected URL's until it stopped. I found them by using the 'Top Traffic by domain' report. We had about 250-300 students using it across the school and they where all very annoyed i've had teachers commenting on how they have been saying they where told it could never be blocked etc etc. If you want the list of URL's i have blocked and confirmed the app has stopped working please PM me i don't want to publicise it as it was about 2 days work!!! 1
BohuntIT Posted March 27, 2018 Posted March 27, 2018 We are facing the same issue, with X-VPN now... Is it ok if I send you a PM? Many thanks!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now