jhothersall Posted February 20, 2020 Posted February 20, 2020 Morning All, Just one to watch out for, we are a BTLS Customer using NetSweeper filtering. We had a incident a few weeks ago where a student managed to run the Brave Browser on Windows (Sophos Application Control reported it to me), but as not a local Admin he could run it. After questions why the student was using this ... after we have Google Chrome deployed and managed, you can bypass the filter via feature in Brave- https://support.brave.com/hc/en-us/articles/360018121491-What-is-a-Private-Window-with-Tor- NetSweeper are aware, (Bug ticket 12549), they say this should be also address at the Firewall level but as TOR uses different TLS Ports this isn't possible. What are people thoughts?
jhothersall Posted February 20, 2020 Author Posted February 20, 2020 I have found that the "Private Tor Tab" do go via Brave, so if you block "brave.com" & "bravesoftware.com" this will stop it from working. The application if downloaded will install into C:\User\%username%\AppData\Local\BraveSoftware if you press No on the UAC Box. I have setup a Software Restriction Policies in Group Policy to stop application from running in this path.
Opendium_Steve Posted February 20, 2020 Posted February 20, 2020 Not done any extensive testing on this, but one of our support team has briefly tested it here (with an Opendium UTM, rather than Netsweeper, but some of this should be relevant to all filters) and reports that: * If the UTM is set to transparently proxy HTTP, HTTPS, DNS and NTP traffic, and block everything else, Brave fails to connect. (This is the default config). * Deep packet inspection correctly identifies this as TOR traffic, so even if the firewall is configured to allow some other traffic, this application's connections are blocked unless you've configured some very permissive allow rules that do not utilise deep packet inspection or suitable destination filters. So even if your firewall doesn't do deep packet inspection, so long as you're transparently proxying all HTTP/HTTPS traffic and don't have firewall rules which allow traffic to the whole of the internet, it seems that this application should be blocked. 1
mavhc Posted February 22, 2020 Posted February 22, 2020 The point of TOR is to avoid being filtered, so mostly just only allow code to run from places users can't write to using SRP. Next block everything by default, so only access to internet is via a proxy. DNS via your DNS server, HTTP/S via your web filter.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now