PDA

View Full Version : Work web filters...


Will
06-11-2007, 14:15
Well I managed 4 months without any problems browsing BD - however this week they appear to have blocked it! :( Facebook however isn't :huh:?

Anyway, all I did was change the DNS servers on my local pc and hey presto I can browse. The rest of my work happens via a Citrix session to which I obviously have no access or control over settings. So fortunately my local pc without being logged onto Citrix gives me a route to the internet. Then I have to change my DNS servers back to the work ones so I can log onto my various systems - but once logged in (it's a persistent session) I can change the DNS back to my DNS servers.

How long will it take them to work it out and stop my browsing? Surely if they were blocking it via DNS lookups, if I'm using an external DNS and still have a route to the internet I shouldn't have any problems no? Obviously within my Citrix session it's an other issue, but why would I browse within Citrix?! :p

Do you give me another 4 months? Or is there not much more they can do?

Mark
06-11-2007, 14:37
You sure it's not just your local DNS servers getting fubar'd with stale data?

PS - if you have access to change DNS servers then you probably have access to edit \windows\system32\drivers\etc\hosts. Shove the IP address in there. DNS servers be damned. Ha! :)

This does of course mean they can see you're browsing BD, but there are far easier ways to find this out anyway.

Will
06-11-2007, 14:44
Nah it comes up with a webfilter error (not sure what software they use.) As soon as I put in my DNS server it works fine. I don't want to edit my host list (I did think of that) because obviously it's a pain in the arse and I don't particularly want them to see me coming online. Though I could set up a couple of batch files to change my dns servers easily enough.

So how else would they monitor my browsing activity? I suppose it's all IP based and they can just reverse DNS it?

Davey_Pitch
06-11-2007, 15:06
Do you go through a work proxy at all? That's how I monitor the kids here, and no matter if they could change DNS or not, if they come through the proxy whatever they do I can watch it and see. Your work could well have something like that in place.

Will
06-11-2007, 15:25
Possibly, what's the easiest way to tell? they don't mind occasional browsing but I think I'm the only one that logs onto forums so it's a bit obvious, hotmail and so on aren't an issue. It's not an overly important issue, but I just don't want them to bother me :p

Mark
06-11-2007, 15:46
Knocked this up for you.

http://www.markvgray.com/header.php

Will
06-11-2007, 17:30
Ohh cool - I'll try it tomorrow when I'm back at work! :)

Will
07-11-2007, 06:42
Well from work I get:

You're not using a proxy, or the proxy isn't detectable.

Here's the rest of the information relating to your request:


Obviously it's not conclusive but it's a start! Woohoo it means I can be naughty! :D :cool:

Feek
07-11-2007, 09:54
No it doesn't, Will. At the moment we bypass the proxy in here for our unofficial web browsing but we're about to add a monitoring system which sits on a hub plugged into our internet router. All internet traffic will go via that hub and as it's not a switch, all traffic will go down all ports so whether people have bypassed the proxy or not, their traffic will be monitored and logged.

Currently the proxy hole is known about by all in the department so it's not an issue but once we fix it and the monitoring goes in then we're all going to have to be careful.

So just because you're not going via a proxy, it doesn't mean you're not being watched or checked upon.

Will
07-11-2007, 10:09
Well I'm only on here and ocuk, as well as bbc news and google searches it's not really in breach of any of the IT policies. Besides, I don't really care if they're watching, I just don't want the sites blocked!

Thanks for the info though Feek. :)

Dr. Z
07-11-2007, 15:12
If you have access to port 22 you could always fire up an SSH session to a box at home and forward all your traffic down that tunnel. No way on earth they can see what you are doing that way :)

Mark
07-11-2007, 15:27
T'is what I do.

They can of course see the SSH tunnel though which might raise eyebrows (though it hasn't for me, yet, touch wood).