James2k Posted February 26, 2008 Posted February 26, 2008 Hi, my first post. Ok.. We have an ISA server running 2004 and we also have the LGFL filtering proxy... But yet the kids can still get on https://www.rainlock.com/ even though every variant has been banned/added to every deny list. And im starting to pull out my hair with frustration at this site, as I cannot find a way of properly banning it... Would like to know if anybody else out in this mass community has found a way of blocking it? Many thanks James
strawberry Posted February 26, 2008 Posted February 26, 2008 if you have your own dns you could change the record for that site?.
mattx Posted February 26, 2008 Posted February 26, 2008 Hi, my first post. Ok.. We have an ISA server running 2004 and we also have the LGFL filtering proxy... But yet the kids can still get on https://www.rainlock.com/ even though every variant has been banned/added to every deny list. And im starting to pull out my hair with frustration at this site, as I cannot find a way of properly banning it... Would like to know if anybody else out in this mass community has found a way of blocking it? Many thanks James We don't run ISA server, we use Navaho - I have managed to ban most proxy sites by just blocking any site which has the word 'proxy' or ' proxies' in - is there a way of doing this on your network ?
ArchersIT Posted February 26, 2008 Posted February 26, 2008 Hi, my first post. Ok.. We have an ISA server running 2004 and we also have the LGFL filtering proxy... But yet the kids can still get on https://www.rainlock.com/ even though every variant has been banned/added to every deny list. And im starting to pull out my hair with frustration at this site, as I cannot find a way of properly banning it... Would like to know if anybody else out in this mass community has found a way of blocking it? Many thanks James From http://www.microsoft.com/technet/isa/2004/plan/faq-urldomainnamesets.mspx For HTTPS traffic, URL sets are only processed if the URL does not have a path specified. For example, http://a.com or "a.com". If the URL has a path specified (even "/"), it is ignored for HTTPS traffic. It looks like this may help as you have listed the url with a trailing / Cheers Jonathan
ArchersIT Posted February 26, 2008 Posted February 26, 2008 We don't run ISA server, we use Navaho - I have managed to ban most proxy sites by just blocking any site which has the word 'proxy' or ' proxies' in - is there a way of doing this on your network ? If you mean blocking the word proxy in the URL, then yes this is possible in ISA 2004 by RMC on the rule and selecting configure http. You can then put in a signature to ban based on the response or request headers, url, bodies etc. We use this for games websites, with a whitelist higher up the order to allow access to educational games sites. Jonathan
spc-rocket Posted February 26, 2008 Posted February 26, 2008 Hi, my first post. Ok.. We have an ISA server running 2004 and we also have the LGFL filtering proxy... But yet the kids can still get on https://www.rainlock.com/ even though every variant has been banned/added to every deny list. And im starting to pull out my hair with frustration at this site, as I cannot find a way of properly banning it... Would like to know if anybody else out in this mass community has found a way of blocking it? Many thanks James Hi James, One of the way to block it wouldbe to use the hosts file on the isa server. Add an entry like following 127.0.0.1 rainlock.com Add the above line to the hosts file on the isa server as i said and then try it. I'm assuming you have tried banning using domain name sets. Ash.
James2k Posted February 26, 2008 Author Posted February 26, 2008 Thank you all very much for all your replies I will reply back when I have found which method works the best.... Me and my hair thank you
mattx Posted February 26, 2008 Posted February 26, 2008 If you mean blocking the word proxy in the URL, then yes this is possible in ISA 2004 by RMC on the rule and selecting configure http. You can then put in a signature to ban based on the response or request headers, url, bodies etc. We use this for games websites, with a whitelist higher up the order to allow access to educational games sites. Jonathan Not just in the URL field, I mean on the actual page the person is viewing. We are able to block pages with certain words on..... I just feel sorry for the people of Scunthorpe...;-)
6Foot2 Posted February 26, 2008 Posted February 26, 2008 We are using a rather dated version of ISA [3.0.1200.166] However when I come acroos a site that I can't block, like the one described, I can sometimes block it by blocking an IP range, so for www.rainlock.com I would block from 69.64.85.158 to 69.64.85.158 This has got me out of a hole more than once. You might be able to try it on your ISA?
ArchersIT Posted February 26, 2008 Posted February 26, 2008 Not just in the URL field, I mean on the actual page the person is viewing. We are able to block pages with certain words on..... I just feel sorry for the people of Scunthorpe...;-) ISA only likes checking the first few bytes of the body - it warns of performance problems if you check too much (although if the server is not exactly stressed so it would probably be OK). Jonathan
James2k Posted February 28, 2008 Author Posted February 28, 2008 Hi guys and girls.. Found out how to block it... If anyone is having trouble with this site you need to ban a few websites... *.dedicated.* *.dedicated.abac.net *.rainlock.* *.rainlock.com *rainlock* 69-64-84-92.* 69-64-84-92.dedicated.* 69-64-84-92.dedicated.abac.* 69-64-84-92.dedicated.abac.net http://rainlock.* http://rainlock.com http://www.rainlock.com http://www.rainlock.* https://rainlock.* https://www.rainlock.* https://www.rainlock.com https://www.rainlock.com/cgi-bin-index.cgi I know it is a few sites but there are different variants and I personally wanted to make sure that the kids couldn't get on this... If all the sites are added to your deny list or ban list the site should come back with a site not found error. I feel my hair growing back ....
James2k Posted March 3, 2008 Author Posted March 3, 2008 Seems that banning them sites was only a small fix.... Any other ideas? Many Thanks.
tom_newton Posted March 3, 2008 Posted March 3, 2008 A small fix in what way? They've found new ones? Tom
James2k Posted March 3, 2008 Author Posted March 3, 2008 I think the site has done something. I have got Synetrix to sort it out as i've run out of ideas...
strawberry Posted March 4, 2008 Posted March 4, 2008 try doing it in dns mate, create a forward lookup zone called rainlock.com and point it at something that will spook the kids, like webmail or google, or a holding page with there name , the aup and a printing icon.
tech_guy Posted March 4, 2008 Posted March 4, 2008 try doing it in dns mate, create a forward lookup zone called rainlock.com and point it at something that will spook the kids, like webmail or google, or a holding page with there name , the aup and a printing icon. We just send them somewhere totally uncool, such as: http://www.sclub-usa.com/ or: http://barbie.everythinggirl.com/ Seems to do the trick!
iseegreen Posted October 20, 2010 Posted October 20, 2010 yawn....so have you guys mangeed to block it yet hmmmm?
iseegreen Posted October 20, 2010 Posted October 20, 2010 We just send them somewhere totally uncool, such as: Universal Motown Records Group or: Barbie.com: Games & Activities for Girls Seems to do the trick! wut are you 5 O.o????
Domino Posted October 20, 2010 Posted October 20, 2010 yawn....so have you guys mangeed to block it yet hmmmm? As the post is from 2008 I, imagine so....congrats on staying current
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now