Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: filtering porn
From: "Bryan D. Boyle" <bdboyle @ maverick . erenj . com>
Date: Mon, 17 Jul 1995 07:52:24 -0400
To: firewalls @ greatcircle . com
In-reply-to: Dave Wade <dw @ salford-software-services . co . uk> "Re: filtering porn" (Jul 17, 9:44am)
Posted-date: Mon, 17 Jul 1995 07:52:26 -0400
References: <199507171006 . DAA09982 @ miles . greatcircle . com>

On Jul 17,  9:44am, Dave Wade wrote:
> Subject: Re: filtering porn
> Hi folks,
>  Assuming you have a list of sites containing erotica what do you do if
> there are other legit things at that site that your users might need ??
>     Yours
>         Dave Wade. dw @
 sss .
 co .
 uk
>-- End of excerpt from Dave Wade

Depending on how the firewall passes the http stuff (as in a cern proxy on
an inside machine talking socks thru the screen to the application server
on the outside...), you may be able to filter on a url-based scheme, and
point the offending (without getting into a porno/art discussion here, ok?)
page at some other, perhaps warning, page.

For instance, using the CERN http server in proxy mode (admitedly the CERN
server is a monolithic, large, complex piece of C code...which is why
it runs on an inside machine...:)), in the /etc/httpd.conf file, there
is the provision to map any page (and this includes wildcarded pages
that are below the one in question...) to some other page.  So, you can
say something like:

Map http://www.penthousemag.com/* http://www.blarg.com/no-no.html

(put this before the Pass: list...).

and _any_ page at penthousemag.com will be rerouted to your own no-no.html
page...

using this same logic, you can say:

Map http://www.nice.site.com/~luser/smut/* http://www.blarg.com/no-no.html

and mr. luser's smut directory will be remapped, however, his other
info, if in other directories, will not be (I would, for sanity sake, however,
move the wildcard up one level, however...:)).

(btw, you should know that socks is also configured so that sites like
penthousemag.com and playboy.com, etc, are, in their entirety, rejected...)

It is not so much a case of that dreaded word, censorship, but, since the
owner of the facility and business has decided that access to certain material
(and this could be dilbert cartoons at some point...) is not desired, it
is enforcing the company standards.

Others may argue that letting people know that they shouldn't waste company
resources on access to egregiously non-business sites is enough, but, in
this case, the company decided, as was their right as the people paying for
the connection, to take a more proactive approach.

YMMV, obviously.


-- 
Bryan D. Boyle           | "The real difficulty in changing any enterprise lies
#include <disclaimer>    | not in developing new ideas, but in escaping from
EMAIL: bdboyle @
 erenj .
 com | the old ones."  --John Maynard Keynes
---------<URL:http://www.access.digex.net/~bdboyle/index.html>-----------



References:
Indexed By Date Previous: Re: Oracle Thru Firewall
From: pauck @ rs3 . wmd . de (Marco Pauck)
Next: [Q] Radius specs.
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Indexed By Thread Previous: Re: filtering porn
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Next: Re: filtering porn
From: o001hee @ MINOCW . NL (Marco Heemskerk)

Google
 
Search Internet Search www.greatcircle.com