Jump to content

Recommended Posts

Posted (edited)
Could use X-{censored} :p Edited by ZeroHour
edited to hide the keyword to stop overblocking - ZH
  • Thanks 1
Posted
What filter do you use?

Link2ICT use McAfee Web Gateway.

 

I'm sure it happened ages ago too. Raised a call to get them to unblock.

  • Thanks 1
Posted

I called it in first thing, so far the replies have been :

2nd message

 

The recategorisation request to change from Medium to Minimum has been declined by McAfee. Typically, this relates to the site being on a shared server/group of IP's whereby one has been compromised in some way. I will speak to McAfee to ascertain the root reason for the change and update you.

 

 

 

1st message

 

Whilst the category (Business/Technical Forums) is whitelisted for all schools, it appears as though the Reputation of edugeek.net has changed from Minimal Risk to Medium Risk.

  • Thanks 2
Posted (edited)
I called it in first thing, so far the replies have been :

2nd message

 

The recategorisation request to change from Medium to Minimum has been declined by McAfee. Typically, this relates to the site being on a shared server/group of IP's whereby one has been compromised in some way. I will speak to McAfee to ascertain the root reason for the change and update you.

 

 

 

1st message

 

Whilst the category (Business/Technical Forums) is whitelisted for all schools, it appears as though the Reputation of edugeek.net has changed from Minimal Risk to Medium Risk.

It could be the AWS ELB (elastic load balancer) ip pool. Basically ELB is managed so we cant control its ip address but it also doesnt strictly host anything. ELB is a service used by a huge amounts of companies hosting via AWS so using its IP pool may be a very poor sign of reputation.

You can tell them its through the EU-WEST AWS ELB IP Pool.

Edited by ZeroHour
  • Thanks 1
Posted

Latest reply

Many thanks for the additional information. The McAfee Reputation Score is an added dynamic (along with multiple other metrics) to check the level of safety against any website/IP/host. The most basic example would be a website hosted on a server with other websites, one of which becomes compromised. McAfee will see the traffic/viruses/spam coming from this IP and will change its reputation as a result. All McAfee customers which use reputation scoring will be affected (not just BGfL Schools)

 

 

 

Clearly edugeek has had no issues for years and now the reputation score has changed - this does not demonstrate that the IP/server/host that the edugeek site resides on is safe however. Of course, it could be an error on McAfee's part and we have an open call request with them querying why the reputation score has changed.

 

 

 

It would be risky to suggest AWS cannot be compromised. A metric of sorts must have changed in order for McAfee to change the reputation level of the site. I'll update when i hear back from McAfee.

  • Thanks 1
Posted (edited)
Latest reply

Many thanks for the additional information. The McAfee Reputation Score is an added dynamic (along with multiple other metrics) to check the level of safety against any website/IP/host. The most basic example would be a website hosted on a server with other websites, one of which becomes compromised. McAfee will see the traffic/viruses/spam coming from this IP and will change its reputation as a result. All McAfee customers which use reputation scoring will be affected (not just BGfL Schools)

 

 

 

Clearly edugeek has had no issues for years and now the reputation score has changed - this does not demonstrate that the IP/server/host that the edugeek site resides on is safe however. Of course, it could be an error on McAfee's part and we have an open call request with them querying why the reputation score has changed.

 

 

 

It would be risky to suggest AWS cannot be compromised. A metric of sorts must have changed in order for McAfee to change the reputation level of the site. I'll update when i hear back from McAfee.

Traffic cant be sent out from ELB, its only incoming from external/one way so their ip wouldnt have sent out malware, you can only add internal servers to the elb and not outside ip addresses. I am curious why McAfee has changed the status, ELB changes our external ip very regularly (several times an hour) depending on which ELB node is dealing with the request and the last few ip's I have checked have not been scored negatively. Its interesting whats going on, thanks for chasing this. AWS can be compromised in the sense a poor server setup could allow another customer using ELB to potentially tarnish an ip but using IP metrics for ELB ip's is the wrong approach due to the nature of what it would block. Its like blocking cloudflare's ip ranges because 1 site proxying through them is nefarious, the blocking based on ip would be disproportionate.

 

I could try rerouting things but I suspect McAfee wont see the change quickly and it will not update for a while. If it was realtime then it should be very temporary unless they applied a medium risk to a large swathe of ELB ip addresses.

Edited by ZeroHour
Posted

This is a tricky situation to gauge, however I'm sure we'd have seen this problem more often if filtering companies treat all websites the same (coming from the same public IPs).

 

If a threat has been detected, then it surely should be possible to identify the specific URL which is the source, rather than block everything from said IPs.

Posted
This is a tricky situation to gauge, however I'm sure we'd have seen this problem more often if filtering companies treat all websites the same (coming from the same public IPs).

 

If a threat has been detected, then it surely should be possible to identify the specific URL which is the source, rather than block everything from said IPs.

 

Yeah its curious how it does its grading, like you say I would have thought this would have hit other blocking before but its possible it was just dismissed in the past.

Posted (edited)

We appear to have dropped down to minimal risk now so hopefully it will be working for you all tomorrow. I have been reaching out to McAfee as well but no proper response yet as to why it was increased.

 

EDIT: Just got a reply saying it had been decreased but no explanation as to why.

Edited by ZeroHour
  • Thanks 3
Posted

From Link2ICT - Final message

 

It appears as though McAfee have recategorised edugeek.net as Minimal Risk (see attached image). The site will now be accessible as before. Whilst this is a dynamic categorisation (Minimal, Medium, High Risk) we do err on the side of caution (and block) when a reputation score changes.

 

All working now :-)

  • Thanks 3
Posted
Indeed can confirm it's working here too. I think it was either human error or maybe they've isolated it to the specific URL as I speculated in my previous message.
  • Thanks 2
Posted

One time one of our major competitors blocked our main website on their filtering system so their schools couldn't look at alternate suppliers saying it was classed as "proxy avoidance / hacking".

 

An honest mistake they claimed, cough splutter :)

 

Dave

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...