College Network Woes...

Jeb_RadecJeb_Radec Join Date: 2002-08-09 Member: 1128Members
<div class="IPBDescription">Defeating the mighty proxy.</div> Being a long time member of the NS community I have seen the very intelligent crowd that NS attracts so I thought it would be as good a place as any to start my war on my college proxy server. The entire time I've been here I've been using all the tricks I learned in high school to get around the blocked sites (Not just porn, they block EVERYTHING from game sites to FTP ports to Telnet ports to IRC to freaking everything.) and slowly one by one they have caught on and killed every trick I have thrown their way. So it's time to get serious.

The Service they use is called <a href='http://www.websense.com/' target='_blank'>Websense</a>. From what i can gather it's primary use is for large corporate networks who want to restrict employees net traffic. It all runs through a proxy server at internal IP 128.95.219.192 port 3128. Which if you plug into your browser you'll see is an interesting distributed networking platform of some sort. Now a quick read of the page also reveals this is an open source project hosted on sourceforge.net which means there should be plenty of documentation on it, but as of yet I have only found very generic broad base descriptions like "facilitates planetary scale projects" rriigghhtt....

Any way A deeper look at the websense site reveals all the admin and install info files which could yield some interesting discoveries but as of yet has not.

Also and here is the part that **** me off and sent me on this crusade... When a page is blocked it comes up with a screen saying why its blocked and such, there is also a link to "Learn about your access rights and privileges" and when you click it the link is broken...

When i begin to mess with the proxy server I get messages like:

"You are trying to use a node of the CoDeeN CDN Network. Your IP address is not recognized as a valid PlanetLab address, so your request rate is being limited."

I will be working hard on this if any one has any experience with this or anything like it I’d love some help!

Comments

  • ZeroByteZeroByte Join Date: 2002-11-01 Member: 3057Members
    edited December 2003
    Try this for getting stuff outside the 80 port range: <a href='http://desproxy.sourceforge.net/' target='_blank'>http://desproxy.sourceforge.net/</a>
  • RellixRellix Join Date: 2003-02-15 Member: 13572Members, Constellation, Reinforced - Shadow
    My school uses the same system, it sucks.
  • ZelZel Join Date: 2003-01-27 Member: 12861Members
    edited December 2003
    go down to the ITS dept and tell them you need IRC access for a science project and they should really tell you how to get access.... assuming the school is worth going to

    edit: WHOA desproxy works! kazaa over http bypasses our network's bandwidth throttling.
  • Spyder_MonkeySpyder_Monkey Vampire-Ninja-Monkey Join Date: 2002-01-24 Member: 8Members, NS1 Playtester, Contributor
    edited December 2003
    <a href='http://www.bluecoat.com' target='_blank'>Bluecoat Systems Incorporated</a>

    Finding the admin port on the Proxy isn't going to help you, as it only allows authorized IP Addresses to administer the machine.

    However, if you can get ahold of the localpolicy file that it reads to restrict access, you can go to work.
    <!--c1--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>CODE</b> </td></tr><tr><td id='CODE'><!--ec1-->
    <proxy>
               url_domain=//natural-selection.org content_filter_override(yes)
    <!--c2--></td></tr></table><span class='postcolor'><!--ec2-->

    Is the only line you'll need. You'll have to wait until the appliance is reset, or the policy is reinstalled for this to take, but any self-respecting corporation reboots their systems nightly.

    If BlueCoat isn't the type of proxy your company uses, just change the syntax as necessary.

    Also, another little trick if it's a bluecoat... the <proxy> layer reads the access/deny list until it finds a match, and then exits... so if you add...

    <!--c1--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>CODE</b> </td></tr><tr><td id='CODE'><!--ec1-->
    <proxy>  
        ALLOW condition=PORTS exit

    define condtion PORTS
             url_port 80
             url_port 443
             url_port 6667
    end condition PORTS
    <!--c2--></td></tr></table><span class='postcolor'><!--ec2-->

    It will see you're trying to go through the port, and then exit that layer. You'll still need to bypass the websense filter, but the content_filter_override command can be used to do so.
  • Nemesis_ZeroNemesis_Zero Old European Join Date: 2002-01-25 Member: 75Members, Retired Developer, NS1 Playtester, Constellation
    All I can say is "Good luck. You'll need it <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif'><!--endemo-->"
  • Jeb_RadecJeb_Radec Join Date: 2002-08-09 Member: 1128Members
    found some free public proxies that are working for the time being!
  • RellixRellix Join Date: 2003-02-15 Member: 13572Members, Constellation, Reinforced - Shadow
    So in plain easy english can someone explain how I can bypass the webspense thing and acces ns.org.
  • cshank4cshank4 Join Date: 2003-02-11 Member: 13425Members
    <!--QuoteBegin--Rellix+Dec 14 2003, 02:19 PM--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Rellix @ Dec 14 2003, 02:19 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> So in plain easy english can someone explain how I can bypass the webspense thing and acces ns.org. <!--QuoteEnd--> </td></tr></table><span class='postcolor'> <!--QuoteEEnd-->
    Grab a subterranian hover craft, a chick or 5 in tight leather, and a computer nut and a balding black dude with snap on sun glasses, teleport inot the school with an ungodly amount of weapons and use your kung fu to hax0r it.


    Relly though, Id just do a simple request to unblock gaming sites to the admin.
  • RellixRellix Join Date: 2003-02-15 Member: 13572Members, Constellation, Reinforced - Shadow
    Unfortunatly my Secondary School is not in controll, we cant do part of our course because its blocked <!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused.gif' border='0' style='vertical-align:middle' alt='confused.gif'><!--endemo--> we are part of the glasgow schools network run by some dumba** company, it took them 3 weeks to get rid of msblaster.... and the same people controll whats blocked and whats not.
  • taboofirestaboofires Join Date: 2002-11-24 Member: 9853Members
    Here's the disclaimer for you: the fine print of your usage agreement for the internet connection probably includes something about intentionally bypassing something like that is an academic integrity violation, which mean you = screwed.
Sign In or Register to comment.