Jump to content

Recommended Posts

Posted

Morning All,

 

Just one to watch out for, we are a BTLS Customer using NetSweeper filtering.

 

We had a incident a few weeks ago where a student managed to run the Brave Browser on Windows (Sophos Application Control reported it to me), but as not a local Admin he could run it.

 

After questions why the student was using this ... after we have Google Chrome deployed and managed, you can bypass the filter via feature in Brave- https://support.brave.com/hc/en-us/articles/360018121491-What-is-a-Private-Window-with-Tor-

 

NetSweeper are aware, (Bug ticket 12549), they say this should be also address at the Firewall level but as TOR uses different TLS Ports this isn't possible.

 

What are people thoughts?

Posted

I have found that the "Private Tor Tab" do go via Brave, so if you block "brave.com" & "bravesoftware.com" this will stop it from working.

 

The application if downloaded will install into C:\User\%username%\AppData\Local\BraveSoftware if you press No on the UAC Box.

 

I have setup a Software Restriction Policies in Group Policy to stop application from running in this path.

Posted

Not done any extensive testing on this, but one of our support team has briefly tested it here (with an Opendium UTM, rather than Netsweeper, but some of this should be relevant to all filters) and reports that:

* If the UTM is set to transparently proxy HTTP, HTTPS, DNS and NTP traffic, and block everything else, Brave fails to connect. (This is the default config).

* Deep packet inspection correctly identifies this as TOR traffic, so even if the firewall is configured to allow some other traffic, this application's connections are blocked unless you've configured some very permissive allow rules that do not utilise deep packet inspection or suitable destination filters.

 

So even if your firewall doesn't do deep packet inspection, so long as you're transparently proxying all HTTP/HTTPS traffic and don't have firewall rules which allow traffic to the whole of the internet, it seems that this application should be blocked.

  • Thanks 1
Posted

The point of TOR is to avoid being filtered, so mostly just only allow code to run from places users can't write to using SRP.

 

Next block everything by default, so only access to internet is via a proxy. DNS via your DNS server, HTTP/S via your web filter.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...