andy_b Posted October 4, 2017 Posted October 4, 2017 Seems edugeek is blocked this morning as: Technical/Business forums
elsiegee40 Posted October 4, 2017 Posted October 4, 2017 (edited) @mikeprice has the same problem. At least they got the correct category Edited October 4, 2017 by elsiegee40
ZeroHour Posted October 4, 2017 Posted October 4, 2017 Seems edugeek is blocked this morning as: Technical/Business forums What filter do you use?
GTX Posted October 4, 2017 Posted October 4, 2017 (edited) Could use X-{censored} Edited October 4, 2017 by ZeroHour edited to hide the keyword to stop overblocking - ZH 1
andy_b Posted October 4, 2017 Author Posted October 4, 2017 What filter do you use? Link2ICT use McAfee Web Gateway. I'm sure it happened ages ago too. Raised a call to get them to unblock. 1
alan-d Posted October 4, 2017 Posted October 4, 2017 I called it in first thing, so far the replies have been : 2nd message The recategorisation request to change from Medium to Minimum has been declined by McAfee. Typically, this relates to the site being on a shared server/group of IP's whereby one has been compromised in some way. I will speak to McAfee to ascertain the root reason for the change and update you. 1st message Whilst the category (Business/Technical Forums) is whitelisted for all schools, it appears as though the Reputation of edugeek.net has changed from Minimal Risk to Medium Risk. 2
ZeroHour Posted October 4, 2017 Posted October 4, 2017 (edited) I called it in first thing, so far the replies have been : 2nd message The recategorisation request to change from Medium to Minimum has been declined by McAfee. Typically, this relates to the site being on a shared server/group of IP's whereby one has been compromised in some way. I will speak to McAfee to ascertain the root reason for the change and update you. 1st message Whilst the category (Business/Technical Forums) is whitelisted for all schools, it appears as though the Reputation of edugeek.net has changed from Minimal Risk to Medium Risk. It could be the AWS ELB (elastic load balancer) ip pool. Basically ELB is managed so we cant control its ip address but it also doesnt strictly host anything. ELB is a service used by a huge amounts of companies hosting via AWS so using its IP pool may be a very poor sign of reputation. You can tell them its through the EU-WEST AWS ELB IP Pool. Edited October 4, 2017 by ZeroHour 1
alan-d Posted October 4, 2017 Posted October 4, 2017 Latest reply Many thanks for the additional information. The McAfee Reputation Score is an added dynamic (along with multiple other metrics) to check the level of safety against any website/IP/host. The most basic example would be a website hosted on a server with other websites, one of which becomes compromised. McAfee will see the traffic/viruses/spam coming from this IP and will change its reputation as a result. All McAfee customers which use reputation scoring will be affected (not just BGfL Schools) Clearly edugeek has had no issues for years and now the reputation score has changed - this does not demonstrate that the IP/server/host that the edugeek site resides on is safe however. Of course, it could be an error on McAfee's part and we have an open call request with them querying why the reputation score has changed. It would be risky to suggest AWS cannot be compromised. A metric of sorts must have changed in order for McAfee to change the reputation level of the site. I'll update when i hear back from McAfee. 1
ZeroHour Posted October 4, 2017 Posted October 4, 2017 (edited) Latest reply Many thanks for the additional information. The McAfee Reputation Score is an added dynamic (along with multiple other metrics) to check the level of safety against any website/IP/host. The most basic example would be a website hosted on a server with other websites, one of which becomes compromised. McAfee will see the traffic/viruses/spam coming from this IP and will change its reputation as a result. All McAfee customers which use reputation scoring will be affected (not just BGfL Schools) Clearly edugeek has had no issues for years and now the reputation score has changed - this does not demonstrate that the IP/server/host that the edugeek site resides on is safe however. Of course, it could be an error on McAfee's part and we have an open call request with them querying why the reputation score has changed. It would be risky to suggest AWS cannot be compromised. A metric of sorts must have changed in order for McAfee to change the reputation level of the site. I'll update when i hear back from McAfee. Traffic cant be sent out from ELB, its only incoming from external/one way so their ip wouldnt have sent out malware, you can only add internal servers to the elb and not outside ip addresses. I am curious why McAfee has changed the status, ELB changes our external ip very regularly (several times an hour) depending on which ELB node is dealing with the request and the last few ip's I have checked have not been scored negatively. Its interesting whats going on, thanks for chasing this. AWS can be compromised in the sense a poor server setup could allow another customer using ELB to potentially tarnish an ip but using IP metrics for ELB ip's is the wrong approach due to the nature of what it would block. Its like blocking cloudflare's ip ranges because 1 site proxying through them is nefarious, the blocking based on ip would be disproportionate. I could try rerouting things but I suspect McAfee wont see the change quickly and it will not update for a while. If it was realtime then it should be very temporary unless they applied a medium risk to a large swathe of ELB ip addresses. Edited October 4, 2017 by ZeroHour
Michael Posted October 4, 2017 Posted October 4, 2017 This is a tricky situation to gauge, however I'm sure we'd have seen this problem more often if filtering companies treat all websites the same (coming from the same public IPs). If a threat has been detected, then it surely should be possible to identify the specific URL which is the source, rather than block everything from said IPs.
ZeroHour Posted October 4, 2017 Posted October 4, 2017 This is a tricky situation to gauge, however I'm sure we'd have seen this problem more often if filtering companies treat all websites the same (coming from the same public IPs). If a threat has been detected, then it surely should be possible to identify the specific URL which is the source, rather than block everything from said IPs. Yeah its curious how it does its grading, like you say I would have thought this would have hit other blocking before but its possible it was just dismissed in the past.
mikeprice Posted October 4, 2017 Posted October 4, 2017 I worried they may have seen the Punny Thread I mean have you SEEN the stuff on there
ZeroHour Posted October 4, 2017 Posted October 4, 2017 (edited) We appear to have dropped down to minimal risk now so hopefully it will be working for you all tomorrow. I have been reaching out to McAfee as well but no proper response yet as to why it was increased. EDIT: Just got a reply saying it had been decreased but no explanation as to why. Edited October 4, 2017 by ZeroHour 3
alan-d Posted October 4, 2017 Posted October 4, 2017 If Link2ICT give me any more info tomorrow I'll post it. (Yea - I know - stop giggling! ) 2
mikeprice Posted October 5, 2017 Posted October 5, 2017 IT'S BACK!!! Normal service has been resumed at least in Halton YMMV 3
alan-d Posted October 5, 2017 Posted October 5, 2017 From Link2ICT - Final message It appears as though McAfee have recategorised edugeek.net as Minimal Risk (see attached image). The site will now be accessible as before. Whilst this is a dynamic categorisation (Minimal, Medium, High Risk) we do err on the side of caution (and block) when a reputation score changes. All working now :-) 3
Michael Posted October 5, 2017 Posted October 5, 2017 Indeed can confirm it's working here too. I think it was either human error or maybe they've isolated it to the specific URL as I speculated in my previous message. 2
SchoolsBroadband Posted October 10, 2017 Posted October 10, 2017 One time one of our major competitors blocked our main website on their filtering system so their schools couldn't look at alternate suppliers saying it was classed as "proxy avoidance / hacking". An honest mistake they claimed, cough splutter Dave
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now