Jon's Network

Network Security News, Analysis and Ephemera

Jon's Network - Murrieta, CA

Ultrasurf

  • Astaro Now Blocks UltraSurf
  • Virustotal Ultrasurf Results
  • How to Block UltraSurf et al. with Sophos
  • Blocking Ultrasurf with a Sonicwall Application Firewall
  • Latest entries to this category....

    Astaro Now Blocks UltraSurf

    February 26th, 2009 · 8 Comments

    Astaro now blocks Ultrasurf with version 7.4. The need and difficulty of this task for schools are so great that Astaro issued a press release to announce the new feature. Apparently they are doing this using SSL inspection (outbound SSL proxy) as opposed to using application signatures. Outbound SSL proxies introduce a new range of [...]

    [Read more →]

    Tags: Astaro · Bit9 · Firewall/UTM · Lumension · Ultrasurf · Web Filtering

    Virustotal Ultrasurf Results

    February 26th, 2009 · No Comments

    When you download UltraSurf 9.3, you get a file called u.exe. This file was submitted to Virustotal on 2/26/2009 and the results are here. Only 3 out of 38 companies identified Ultrasurf 9.3 as malware. Fortinet, Prevx1 and Quick Heal of India. Contrast that with this Virustotal scan of UltraSurf 8.8 from 3/13/2008 where 9 [...]

    [Read more →]

    Tags: Anti-Virus · Endpoint Security · Fortinet · Ultrasurf

    How to Block UltraSurf et al. with Sophos

    February 10th, 2009 · No Comments

    Blocking client-server applications like Ultrasurf at the network level can be a pain. Not so much if you have a firewall from Palo Alto Networks or a reasonably sophisticated URL filter like St. Bernard’s iPrism, but if you are constantly playing cat-and-mouse trying to block Ultrasurf et al. on your network you might see if [...]

    [Read more →]

    Tags: Application Control · Sophos · Ultrasurf · iPrism

    Blocking Ultrasurf with a Sonicwall Application Firewall

    January 19th, 2009 · 18 Comments

    Organizations under pressure to keep students and employees from bypassing internet filters using client technologies, like UltraSurf are in a perpetual game of cat and mouse. A network admin I know used these steps to block it on his Sonicwall: Ultrasurf uses “140300000101″ for SSL ehlo messages. If you can block this signature with the [...]

    [Read more →]

    Tags: Firewall/UTM · Palo Alto Networks · Sonicwall · Ultrasurf · Web Filtering