TechMonkey Posted February 9, 2024 Posted February 9, 2024 I am taking a stab in the dark but I think it may be if you have clicked exclude in the safeguarding report. It isn't there if you haven't, it gets created and populated once the button is clicked. Though I may be very wrong. 1
5tu Posted February 9, 2024 Author Posted February 9, 2024 I am taking a stab in the dark but I think it may be if you have clicked exclude in the safeguarding report. It isn't there if you haven't, it gets created and populated once the button is clicked. Though I may be very wrong. Good idea. I would have thought Safeguarding Report Exclusions only exclude things from reporting, not filtering, but maybe that assumption is wrong. If so, the behaviour isn’t documented as far as I can tell.
sigma Posted February 9, 2024 Posted February 9, 2024 crazygames.com and content still accessible for me too despite explicitly being in custom blocked list. I don't get it... EDIT: Content is being loaded from cdn.iubenda.com which falls into a few Smoothwall categories including "Safeguarding Exclusions". I'm guessing Safeguarding Exclusions are always allowed? [ATTACH=CONFIG]70834[/ATTACH] iubenda.com is the accept/reject cookie processing element on the site.
sigma Posted February 9, 2024 Posted February 9, 2024 In addition to crazygames.com there are also following: https://www.crazygames.fi https://www.1001juegos.com https://www.crazygames.nl https://www.crazygames.se https://www.crazygames.co.id https://www.crazygames.ro https://www.crazygames.ru https://www.crazygames.com.ua https://www.crazygames.cz https://www.crazygames.dk https://de.crazygames.com https://www.crazygames.fr https://it.crazygames.com https://www.crazygames.hu https://www.crazygames.no https://www.crazygames.pl https://www.crazygames.com.br https://vn.crazygames.com https://tr.crazygames.com https://gr.crazygames.com https://www.crazygames.com.ua https://ar.crazygames.com https://th.crazygames.com https://kids.crazygames.com
sigma Posted February 9, 2024 Posted February 9, 2024 For Bullet Force: Sorry, I'm not a recent Smoothwall user and now very rusty on how to set it up, so I have to ask: Is your block of grazygames.com "as defined" going to block all these or just http://www.crazygames.com? You need these to belt and braces block it. This will also block it for the other sites that host it. https://api.crazygames.com https://builds.crazygames.com https://files.crazygames.com https://gameframe.crazygames.com https://games.crazygames.com https://pafvertizing.crazygames.com https://videos.crazygames.com https://workers.crazygames.com
sigma Posted February 9, 2024 Posted February 9, 2024 Looks like the content might be loading via https://cdp.cloud.unity3d.com/v1/events and I also see log entries for https://www.semrush.com/website/_next/data/Aib3b30p57Iok7kW8mlIb/gamepluto.com/overview.json?domain=gamepluto.com which Smoothwall categorises as "Safeguarding Exclusions". Device I'm testing with is using the on-prem filter. I'll test a device configured with the cloud filter. Think I'll open a ticket with Smoothwall. Thanks Blocking: https://justbuild.nyc3.cdn.digitaloceanspaces.com seems to stop 1v1.lol and justbuild.lol games from loading past the spinning circle. I don't think it will break anything else, but I can't say I've tested extensivley. It seems to be the game developers CDN. Are these the right games or or there others? 1
sigma Posted February 10, 2024 Posted February 10, 2024 Blocking: https://justbuild.nyc3.cdn.digitaloceanspaces.com seems to stop 1v1.lol and justbuild.lol games from loading past the spinning circle. I don't think it will break anything else, but I can't say I've tested extensivley. It seems to be the game developers CDN. Are these the right games or or there others? As well as observing it accessed when the games loads, its in available versions of source code eg: https://github.com/scheng123321/1v1-lol/blob/master/index.html https://pastebin.com/gMCNeTpS I can't find anything else other than games calling it. 1
5tu Posted February 10, 2024 Author Posted February 10, 2024 As well as observing it accessed when the games loads, its in available versions of source code eg: https://github.com/scheng123321/1v1-lol/blob/master/index.html https://pastebin.com/gMCNeTpS I can't find anything else other than games calling it. Good find @sigma [emoji106] 1
CSmith Posted February 13, 2024 Posted February 13, 2024 (edited) Hi All, @tom_newton has asked me to take a look at this thread and provide any support I'm able to. I'll try to answer any questions I can but it seems like there might be a few different issues here so you'll have to bear with me. First off, we should address the Safeguarding Exclusions category so there's no confusion. This is a Smoothwall owned category that is (mostly) hidden from view. It contains a whole bunch of rules designed to prevent over-reporting in the safeguarding reports and you'll see this crop up in the logs from time to time. It's mostly used to prevent .css, .txt, .json, (...etc) files from raising safeguarding alerts but rest assured that these URLs are still filtered just like any other, and certainly aren't allowed out by default. The gamepluto.com domain is currently categorised as Video Games by both domain/URL and content analysis, so there shouldn't be any need to add this domain to any custom categories providing you have Video Games in a block policy. @gybe78 you've mentioned that you get a blockpage when you access the domain directly but when you search via Google you're able to follow the link and access the site. That certainly shouldn't be the case. I've done a bit of testing and I can confirm that a search in Google for "gamepluto" (or "game pluto") should be caught on content for Video Games, which suggests to me that you either don't have an HTTPs inspection in place and/or - and I suspect this is more likely - you're allowing either google.com or some other google related domains. Would you be able to confirm if you have an HTTPs inspection policy in place or not and then check any custom categories you're currently allowing out to ensure they don't contain anything... Googly... @TechMonkey with regards to Bullet Force on crazygames.com - where students accessing the game directly on crazygames.com or where they accessing the game via other sites? I've checked that domain and can confirm its categorised as Video Games by both URL and content analysis. I've also looked through the list @sigma supplied and all of those are also categorised by content analysis, although we didn't have all those URLs in our database (they will of course be in our categorisation rules from tonight's blocklist update). If students are (or were) able to access Bullet Force on some of those domains then that would suggest to me that an HTTPs inspection policy isn't in place, would you be able to confirm for me? For your information @sigma (and anyone else who might be unawares) there's no need to block all the various subdomain (api. builds. files., etc..) when you add a domain to a custom category. We match greedily so an entry for crazygames.com is effectively matching *.craxygames.com/* Edited February 13, 2024 by CSmith Formatting 1
TechMonkey Posted February 13, 2024 Posted February 13, 2024 Hi All, @TechMonkey with regards to Bullet Force on crazygames.com - where students accessing the game directly on crazygames.com or where they accessing the game via other sites? I've checked that domain and can confirm its categorised as Video Games by both URL and content analysis. I've also looked through the list @sigma supplied and all of those are also categorised by content analysis, although we didn't have all those URLs in our database (they will of course be in our categorisation rules from tonight's blocklist update). If students are (or were) able to access Bullet Force on some of those domains then that would suggest to me that an HTTPs inspection policy isn't in place, would you be able to confirm for me? For your information @sigma (and anyone else who might be unawares) there's no need to block all the various subdomain (api. builds. files., etc..) when you add a domain to a custom category. We match greedily so an entry for crazygames.com is effectively matching *.craxygames.com/* Many thanks for getting back to us. I can confirm currently we are not using HTTPS interception. The oddness was that we could see crazygames.com was filtered but it was getting through. I'm hoping to implement interception over the half term so I will see how it goes.
sigma Posted February 13, 2024 Posted February 13, 2024 (edited) To reiterate, I'm not a Smoothwall customer at the moment. It is one of several very capable filters available. My interest is in maximising the efficiency of blocking, without over blocking regardless of the particular filter used. I cannot emphasise enought that https inspection is essential to give the fine grained control to achieve that. Games sites are no more than clickbait to get advertising clicks. In the worst cases, they serve infected adverts or use bandwidth stealers such as https://arc.io/ . The big sites such as crazygames earn a lot from their worldwide user base, even though the games are free to play. The games are designed to be addicitve and can lead their users onto more serious gaming and gambling. Some of the games are hosted on the domains they are played. They are easy to block Some are hosted on other games sites. For example, Bullet-Force on pacogames.com or coolgamesonline.co.uk is still loaded from crazygames.com. Others are loaded from games Content Delivey Networks that you won't see in a browser url so are a bit more work to block. Don't assume that blocking the url you see will block the game. There are also an increasing number of ever changing Web Proxies from the like of Nebula, Holy Unblocker and Interstellar that are now also loading or hosting these games directly for the Ad revenue. Blocking the ads can be key as some games won't load when the ads are blocked. Whatever you do to block games (and I do), its 100% whack-a mole. Edited February 13, 2024 by sigma
5tu Posted February 13, 2024 Author Posted February 13, 2024 Hi All, @tom_newton has asked me to take a look at this thread and provide any support I'm able to. I'll try to answer any questions I can but it seems like there might be a few different issues here so you'll have to bear with me. First off, we should address the Safeguarding Exclusions category so there's no confusion. This is a Smoothwall owned category that is (mostly) hidden from view. It contains a whole bunch of rules designed to prevent over-reporting in the safeguarding reports and you'll see this crop up in the logs from time to time. It's mostly used to prevent .css, .txt, .json, (...etc) files from raising safeguarding alerts but rest assured that these URLs are still filtered just like any other, and certainly aren't allowed out by default. The gamepluto.com domain is currently categorised as Video Games by both domain/URL and content analysis, so there shouldn't be any need to add this domain to any custom categories providing you have Video Games in a block policy. @gybe78 you've mentioned that you get a blockpage when you access the domain directly but when you search via Google you're able to follow the link and access the site. That certainly shouldn't be the case. I've done a bit of testing and I can confirm that a search in Google for "gamepluto" (or "game pluto") should be caught on content for Video Games, which suggests to me that you either don't have an HTTPs inspection in place and/or - and I suspect this is more likely - you're allowing either google.com or some other google related domains. Would you be able to confirm if you have an HTTPs inspection policy in place or not and then check any custom categories you're currently allowing out to ensure they don't contain anything... Googly... @TechMonkey with regards to Bullet Force on crazygames.com - where students accessing the game directly on crazygames.com or where they accessing the game via other sites? I've checked that domain and can confirm its categorised as Video Games by both URL and content analysis. I've also looked through the list @sigma supplied and all of those are also categorised by content analysis, although we didn't have all those URLs in our database (they will of course be in our categorisation rules from tonight's blocklist update). If students are (or were) able to access Bullet Force on some of those domains then that would suggest to me that an HTTPs inspection policy isn't in place, would you be able to confirm for me? For your information @sigma (and anyone else who might be unawares) there's no need to block all the various subdomain (api. builds. files., etc..) when you add a domain to a custom category. We match greedily so an entry for crazygames.com is effectively matching *.craxygames.com/* Thanks for the post @CSmith. We do have https inspection policies in place and don’t have anything googly whitelisted. The sites mentioned are clearly categorised as Video Games (this is shown in the web filter real-time logs) but somehow students still have access to crazygames. Gamepluto access seems inconsistent. I’m currently away on annual leave until Monday but would appreciate a 2nd / 3rd line engineer picking up my support case when I return on Monday. Thanks 1
5tu Posted February 19, 2024 Author Posted February 19, 2024 This is whack-a-mole..... Just found a student somehow playing games here - poki.com/en/g/bumper-soccer-cars Smoothwall logs show url categorised as "Video Games" and being blocked, except it isn't. Makes no sense @CSmith
sigma Posted February 19, 2024 Posted February 19, 2024 This is whack-a-mole..... Just found a student somehow playing games here - poki.com/en/g/bumper-soccer-cars Smoothwall logs show url categorised as "Video Games" and being blocked, except it isn't. Makes no sense @CSmith Is that the right url as both me and urlscan.io get an ERROR Sorry, the page you requested does not exist on this site. Play a surprise game
LeMarchand Posted February 19, 2024 Posted February 19, 2024 https://poki.com/en/g/bumper-cars-soccer probably. Could they be going through one of those proxy sites?
sigma Posted February 19, 2024 Posted February 19, 2024 Assuming you mean: https://poki.com/en/g/bumper-cars-soccer Blocking poki.io seems to stop the game from loading. I would block poki-gdn.com as well. These would stop the poki games from loading where they are front ended on other sites too. Scan result : https://urlscan.io/result/96d21310-d1aa-4593-b09f-d5373994015f/
5tu Posted February 19, 2024 Author Posted February 19, 2024 Assuming you mean: https://poki.com/en/g/bumper-cars-soccer Blocking poki.io seems to stop the game from loading. I would block poki-gdn.com as well. These would stop the poki games from loading where they are front ended on other sites too. Scan result : https://urlscan.io/result/96d21310-d1aa-4593-b09f-d5373994015f/ Thanks for the post @sigma - have blocked poki.io and pokigdn.com but can't understand why Smoothwall isn't already doing this for us? @tom_newton 1
sigma Posted February 19, 2024 Posted February 19, 2024 Other providers have issues too. I have reported “hundreds” of web proxies to Net******* and I don’t understand why they are not categorised correctly when the there are only about 10 different versions of identical content between them. 1
5tu Posted February 19, 2024 Author Posted February 19, 2024 Whatever I do students can get to games by googling "game pluto" and clicking on search result links. SLT are really not impressed and requesting a change of filtering supplier at our renewal later this year.
LeMarchand Posted February 19, 2024 Posted February 19, 2024 Whatever I do students can get to games by googling "game pluto" and clicking on search result links. SLT are really not impressed and requesting a change of filtering supplier at our renewal later this year. Can't you institute a wildcard block like *q=game+pluto* and/or *q=gamepluto*? 1
5tu Posted February 19, 2024 Author Posted February 19, 2024 (edited) Thanks for the suggestion - this has been added and we'll see if it makes any difference. UPDATE: Made no difference at all! Edited February 19, 2024 by gybe78
Joeloman Posted February 19, 2024 Posted February 19, 2024 (edited) Regarding Poki Smoothwall has changed its categories and added signatures. https://kb.smoothwall.com/hc/en-us/articles/11206334266268-Important-Updates-to-the-Smoothwall-Category-Hierarchy If you look at the list of signatures, you'll see that Poki is listed under Game Stores and Publishers When it is a signature, it blocks everything that belongs to that signature, e.g. poki.io etc. Edited February 19, 2024 by Joeloman 3
5tu Posted February 19, 2024 Author Posted February 19, 2024 (edited) The only possible "google" item I can find being excluded from authentication is "Connect for Chromebooks" in the "Authentication exceptions" Category group. Would someone mind please checking their config to see if this is standard or not? Edited February 19, 2024 by gybe78
CSmith Posted February 19, 2024 Posted February 19, 2024 @gybe78 is there any chance you could DM me a copy of your Smoothwall's archive so I can load it up locally and take a look? 1
5tu Posted February 19, 2024 Author Posted February 19, 2024 @gybe78 is there any chance you could DM me a copy of your Smoothwall's archive so I can load it up locally and take a look? Thanks @CSmith. I think I'd rather share it via my open ticket - ref #490104. I'll upload it now.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now