Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Does Raptor WebNOT Block Legitimate Sites?
From: "-tim thayer" <tthayer @ bbtnet . com>
Date: Tue, 11 Mar 97 10:46:40 PST
To: "Jason H. Lamar" <lamar @ swiftsword . cst . digex . net>, "2LT Jeffery J. Lowder, 333-4615" <LowderJJ . SCB . USAFA @ usafa . af . mil>
Cc: bpetrie @ incc . net, raptor-list @ udc . com, firewalls @ greatcircle . com
In-reply-to: <Pine . SUN . 3 . 94 . 970310120637 . 14039A-100000 @ swiftsword . cst . digex . net>
References: Conversation <Pine . SUN . 3 . 94 . 970310120637 . 14039A-100000 @ swiftsword . cst . digex . net> with last message <Pine . SUN . 3 . 94 . 970310120637 . 14039A-100000 @ swiftsword . cst . digex . net>

We too are discovering the same "feature" in WebNot and would love to see
Raptor encourage CyperPatrol to  only block the actual URLs of sites.  We
currently have to write rules to open the whole site up since we cannot get
as granular as the specific URL. 

-tim thayer
Branch Banking and Trust

----------
> The truncated lists of URLS are a problem. For instance, say I have
> customer http://www.company.com/~smut
> 
> WEBNOT will be truncating them like http://www.company.com/~sm
> 
> This would also block ~smart, ~smack etc.
> 
> This is not a fault of Raptor but the third party solution that they have
> inculcated into their product. This is the fault of the subscription
> service used for WEBNOT. Albeit, Raptor could pressure them
> to only block the actual URLs of sites, this is a common problem with
> subscription/url blocking services like NetNanny and Cyberpilot, which is
> what Raptor is using. 
> 
> - Jason
> 
> On Mon, 10 Mar 1997, 2LT Jeffery J. Lowder, 333-4615 wrote:
> 
> > Hello,
> > 
> > We recently installed Raptor WebNOT to work with our Raptor Eagle 4.0 
> > firewall.  Remember that WebNOT can be used to block access to 
> > 'unauthorized' sites, where 'unauthorized' is defined as sites the
company 
> > doesn't want its employees visiting.
> > 
> > Apparently their database of 'bad' URLs contains many truncated URLs. 
If 
> > the URL is just an IP address, everything works great.  However, if the 
> > URL is more than an IP address -- if the URL contains a directory path,
a 
> > filename, or both -- we've found that the URL is normally truncated
when 
> > listed in the WebNOT database.  For example, the URL for DejaNews
Research 
> > Service,
> > 
> > http://199.86.32.6/members/stick/ 
> > 
> > is stored in the WebNOT database (httprating.db) as
> > 
> > http://199.86.32.6/mem
> > 
> > Now, I don't claim to have detailed knowledge of the computer at 
> > 199.86.32.6, but it stands to reason that there are probably multiple 
> > subdirectories under the /members directory.  Yet Raptor WebNOT blocks 
> > access to ALL of these directories because apparently ONE of them
contains 
> > nudity.
> > 
> > 
> > You can imagine how much I enjoy taking heat from customers because
we're 
> > blocking access to ostensibly legitimate sites.
> > 
> > Am I not understanding something, or is this very poor design on
Raptor's 
> > part?  Is there anyone else out there who uses Raptor WebNOT and has 
> > experienced this problem?
> > 
> > I tried calling Raptor directly to make a bug report, but since I don't 
> > have a maintenance contract with Raptor, the operator at Raptor
customer 
> > support wouldn't even take my call.
> > 
> > Lt Jeff Lowder <lowderjj .
 scb @
 usafa .
 af .
 mil>
> > Chief, Network Security
> > United States Air Force Academy
> > 
> > Disclaimer: The above content does not necessarily represent the views
of 
> > the United States Government or the United States Air Force Academy.
> > 
> 
> Jason H. Lamar
> Team Leader Security Installations; DIGEX INC. 		   
> lamar @
 digex .
 net / 301-847-5158 / 301-847-6215(FAX)   
> -------------------------------------------------
> "Where does he get all of those wonderful Toys?"		
> 				- The Joker to Batman
> 
> 
> 
> 
> 




References:
Indexed By Date Previous: ftp mirroring by putting
From: Justin Vincent <vincentj @ aib . ie>
Next: Re: List removal - use the who cmd people
From: Gary Stanny <stanny @ handset . laa . com>
Indexed By Thread Previous: Re: Does Raptor WebNOT Block Legitimate Sites?
From: "Jason H. Lamar" <lamar @ swiftsword . cst . digex . net>
Next: Re: Does Raptor WebNOT Block Legitimate Sites?
From: Allen Rogers <arogers @ raptor . com>

Google
 
Search Internet Search www.greatcircle.com