altecsole Posted December 7, 2023 Posted December 7, 2023 We currently have a Barracuda Web Security Gateway as our web filter. I've inherited it, and intend to change as soon as the contract finishes, but I'm stuck with it for now. I was checking the web log after school yesterday and noticed repeated suspicious entries for Google, as all requests to Google should be redirected to HTTPS, and the URL pattern was clearly not a web search. I implemented a Regex to block https://www.google.com, and almost immediately watched as the traffic change to connect to http://app.telekom.mk (which is a Telecom from North Macedonia). I blocked this domain, and then the URL changed again to http://www.ws.k12.ny.us (a public school district in New York). The connection was from our BYOD VLAN, and I assume that they were using some kind of domain masking to avoid having to install the Barracuda certificate for SSL inspection? Here's a snip of the log entry. Any thoughts?
danysansum Posted December 7, 2023 Posted December 7, 2023 Morning, I work at a Barracuda MSP and have spoken to the support team about your issue. You are right this does happen if users are trying to avoid installing the Barracuda certificate for SSL inspection. They suggested a couple of things that could help..# 1. Ensure that your SSL inspection policies are configured correctly. Double check whether the WSG is configured to intercept and inspect SSL traffic. Often involves installing the cuda certificate on client device or push it out via group policy. 2. continue blocking websites that arent for educational purposes 3. if possible consider, further segementing your BYOD VLAN from mission critical systems as a preventative measure 4. see if there is a firmware update All else fails, the support team from barracuda will be able to help and jump on a zoom/teams call to assist further-> 0118 338 4602 / [email protected]
altecsole Posted December 7, 2023 Author Posted December 7, 2023 Morning, I work at a Barracuda MSP and have spoken to the support team about your issue. You are right this does happen if users are trying to avoid installing the Barracuda certificate for SSL inspection. They suggested a couple of things that could help..# 1. Ensure that your SSL inspection policies are configured correctly. Double check whether the WSG is configured to intercept and inspect SSL traffic. Often involves installing the cuda certificate on client device or push it out via group policy. 2. continue blocking websites that arent for educational purposes 3. if possible consider, further segementing your BYOD VLAN from mission critical systems as a preventative measure 4. see if there is a firmware update All else fails, the support team from barracuda will be able to help and jump on a zoom/teams call to assist further-> 0118 338 4602 / [email protected] Hi, and thanks for responding. Yes, SSL Inspection is turned on and we do push out the certificate via Group Policy and make available to students to download and install on their own devices for when connecting to our BYOD Wi-Fi network. We do try to keep a balance when blocking websites, but we do use Categories as a general starting point, and then have exceptions as required. Our BYOD is on a seperated VLAN, with ACLs in place to stop access to the rest of our network. Firmware updates are few, and far between. I used a Barracuda WSG in a previous employment, which was about 8 years ago, and it's hardly changed since then. Our current firmware is the latest - v16.0.014, released May 2022. The version previous to that was July 2020. It really doesn't feel like this product is in active development. However, what I'm really interested in is the mechanism that the end user is employing for access. The entries for Google are not web searches, and why, if it is Google, aren't subsequent entries showing an HTTPS connection. It seem that they might be masking their URL in some way? If anyone has any insight, that would be much appreciated.
altecsole Posted January 19, 2024 Author Posted January 19, 2024 An update on this, if anyone is interested. It does look like some students are using web masking to conceal their true destination from our web filter. Luckily, this is fairly easy to spot, as the logs show hundreds of consecutive connections to wikipedia.org. I think that they are using Content Delivery Networks to hide the destination, in the following way. The user's browser connects to a CDN that hosts both a legitimate website (like Wikipedia) and a prohibited website. The user specifies the legitimate website in the initial connection request, but then embeds the prohibited website's address within the encrypted HTTPS traffic. I know some students have the Brave browser on their devices, but I'm unclear whether it can do this, or whether a VPN service is being used. Our web filter contract ends this summer, so I'm now starting to look at replacements, and being able to identify and block this behaviour will be near the top of the list of requirements. In the meantime, I have a very restrictive rule on the web filter, that allows Microsoft 365 only, and user devices that show this pattern are added to it.
altecsole Posted January 19, 2024 Author Posted January 19, 2024 Some single entries in the log which must be linked to this. Blocked now, but worth checking: https://get-xmore-links8.com/ https://netpioneeres.com/y26cbv8zgdmcq3purtuy.png https://api.get-just-api.com/ https://get-xmore-links8.com/ https://websmatrix.com/ https://get-xmore-link3s.com/ https://api.du-just-link.com/ https://get-xmore-link3s.com/
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now