About any non-blocked website can be abused this way. That's why I stated nytimes.com.
DNS
That's the point: Modern policies can prohibit _running_ such tools, at least to a certain level. Not so reliable, but pretty effective.
That's why downloading such utilities being possible, besides circumventing the policies, is no big problem.
Anyway, it also requires you to not run any malware^wcommercial software that employs certain ways of scripting without any or any working policies. And I guess many companies are running MS Office. At this point you've already lost.
Didn't find your answer? Ask the community — no account required.
D
Don Kelloway
It's always been my opinion that the best Acceptable Use Policy (AUP) implements both a quality technical solution and an appropriate educational/training program.
For the technical side of the approach I make it a point to ensure my clients understand that while it is true the issue of objectionable surfing cannot be stopped 100%, the real goal is to make it practically impossible for the casual offender and to deter/hinder the more serious offenders from even trying. Of course reviewing the appropriate Internet related log files and looking for trends will often provide the necessary insight that can lead to closing the door to anything questionable that remains.
D
Don Kelloway
As with anything, IE can be made extremely secure if it has been appropriately configured and locked down to prevent change.
D
Don Kelloway
Is Tracker still around?
Oh the memories...
S
Sebastian Gottschalk
Wrong. There are actually many unpatched security holes in IE that cannot be workarounded with Windows' standard tools, and filtering at a proxy level would break down any website to simply formatted text and tables. Just take - you have the choice: stylesheets cannot be disabled, configuring a user stylesheet doesn't work and stripping all CSS formatting makes websites, well, you know...
S
Sebastian Gottschalk
This contradicts the quality of your technical solution. Such an implementation is usually almost infeasable in terms of resources.
Or not, as in most cases you simply cannot.
D
Don Kelloway
I beg to differ.
Example: If I attempt to display the URL you offer as an example in my configuration of IE. Guess what happens? Absolutely nothing. In fact all I receive is 'Your current security settings do not allow this file to be downloaded" message. Now why do you think that is?
D
Don Kelloway
The quality of the technical solution works perfectly for what is to be expected of it. Of course if you think it's going to make you a PB&J then you're right. It won't.
In respect to the technical solution itself it should be understood that when properly administered it leaves practically little, if any possiblity for circumvention. Of what there is ensuring the appropriate firewall configuration is in place in combination with reviewing the necessary log files and understanding what it is you're looking for, provides the necessary means to prevent what remains.
And yes such an implementation is entirely possible and the resources required are minimal. I've been doing it for almost ten years for companies with as little as five employees to as high as 15,000.
S
Sebastian Gottschalk
A network error.
S
Sebastian Gottschalk
IE's inability to understand what Content-Type: application/xhtml+xml means (hint: it's the correct MIME type for XHTML) without any manual configuration. Obviously you can't even do simplest necessary MIME configuration.
S
Sebastian Gottschalk
When it comes to content filtering and tunneling: You'd wish.
E
E.
If it knew what to do with the request.
So you can resolve the IP using a UDP packet. How do you propose to get a two-way connection going using a UDP53, and browsing myspace using this?
As already stated, all downloads being blocked. Sending a UDP packet does no equal a downloaded utility.
More allusion, and no proof. E.
M
Moe Trin
1036 Standard for interchange of USENET messages. M.R. Horton, R. Adams. December 1987. (Format: TXT=46891 bytes) (Obsoletes RFC0850) (Status: UNKNOWN)
Why don't you read RFC2036 then? Or perhaps you haven't bothered to implement RFC3514 - it _is_ an RFC ya know.
And you are incapable of creating your own local list? Re-read RFC2821 section 7.7 - ALL OF IT.
Again, read RFC2821 section 7.7. The bounces you complain about are due to clueless fools who accept all mail addressed to their domain irrespective of whether the recipient exists or not, then later discovering "Oppsie, I can't deliver this crap - I better tell the sender". Another subset are those who accept the mail, then run it past a virus checker or some such rot, and attempt to inform the purported sender that the mail is somehow infected (even when the virus checker KNOWS that the specific virus they claim to have detected forges the headers). I see no reason to accept any mail from such a b0rked domain. Neither do our users. When these domains try to connect, they get a 553 at the HELO/EHLO stage directing them to a web page that explains why, and gives both a phone number and snail-mail address if they want to discuss it. We get very few complaints.
Old guy
E
E.
Some of his info is actually quite useful and informative. Also, English is not his first language and most disagreements I have had with him are due to this and the resulting misinterpretations. I'd prefer to listen to people, then decide what to do with the info, rather than shut them off after a few sentences.
Despite the non-answers I am getting in this topic i am still prepared to dig for answers. E.
M
Moe Trin
Haven't seen any posts, but then my newsreader filters articles that are cross-posted to alt.pets.*
I think the ferrets finally captured her and handed her over for corrective surgery to remove the vacuum between the ears. The trolls we're seeing now aren't even a tenth as funny.
Old guy
D
Don Kelloway
I think my being facetious escaped you. The browser's inability to display the content is/was intentional on my part as I configured the browser not to do so. In other words, using IE and visiting the URL provided did nothing harmful to my system because my browsers configuration prevents downloads.
D
Don Kelloway
Tunneling is not escapable to detection and content filtering can be applied. Maybe you ought to become more familiar with the content filtering solutions that are available as opposed to what you think they can and can't do.
S
Sebastian Gottschalk
THERE IS NO DOWNLOAD!
This is a standard HTML webpage delivered with the correct MIME type. IE would display it as the webpage it is if either you added the MIME the additional MIME type or if the webserver would deliver is as text/html (which is also correct, but deprecated).
S
Sebastian Gottschalk
So you did not read how he disproved this statement in almost any way?
Not effectively.
I am, I know clearly what can't be accomblished and I can clearly so that those solutions can't do either (or better: exactly because).
S
Sebastian Gottschalk
No, just if it can be used to pass data to someone else in an automated manner.
Get in charge of a certain DNS zone, so having control over the authoritive DNS answers.
Supposed I want to resolve $base64_encoded_data.somedomain.invalid, which I'm in control of. The DNS server will send the correct IP and the response as a TXT, AAAA or PTR record.
Stating that clearly: You are *trying* to block downloads. Me happily assuming that it will generally fail however you try.
Write a VBA macro doing a LoadLibaryEx() and see what it does to Windows XP's SRP.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.