Results 1 to 9 of 9
  1. #1
    Newbie
    Join Date
    Sep 2007
    Location
    Brazil
    Posts
    4

    Default Spyware Blocker Question

    Hi guys, im kind new to Untangle, and Iīve got a question.
    First of all I would like to thank everybody that did and support this software, itīs very good, functionally and graphically speaking.
    Well, my concern is about spyware blocker. I see there are many events that has the "pass" flag on it, even tough they look like spyware to me , like this one 209.62.176.0/19 : Doubleclick (reason In Subnet List)
    Why isnt it blocking such things? Arent they considered spyware? How can I make it block then besides just logging it? I mean, there is no "block" option on "subnet list", just "Log".
    Thanks in advance for your help and patience!

  2. #2
    Untangle Junkie amac's Avatar
    Join Date
    Aug 2007
    Posts
    824

    Default

    Hey,
    I don't quite get where the issue is. I take it that you are blocking some spyware, but not all of it that you would like?
    In the module, what type of mail traffic are you using? SMTP, IMAP, or POP? And which threshold are you set on?
    If you can answer these, we can help out more
    Hope that everything else is going well. Let us know, and welcome to the forums.

  3. #3
    Administrator gotkimchi's Avatar
    Join Date
    Jan 2007
    Location
    Bay Area
    Posts
    2,109

    Default

    welcome to the forums Katabroc... The Untangle spyware blocker module is blocking that subnet. The subnet list is under the block lists tab, meaning it will be blocked. You have the option to log this incident or you can leave the check mark box empty.
    to be understood, you must first understand.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com

  4. #4
    Newbie
    Join Date
    Sep 2007
    Location
    Brazil
    Posts
    4

    Default

    Well, thanks for answering so fast! U guys are awesome.

    But Iīm not quite sure if I said what I wanted to. This is what I get on my Event log :



    Arenīt those requests supposed to be blocked? I mean, if they have "pass" action, they are not being blocked, right?

  5. #5
    Newbie
    Join Date
    Sep 2007
    Location
    Brazil
    Posts
    4

    Default

    Does anybody know something about my question? Thanks

  6. #6
    mdh
    mdh is offline
    Untangle Ninja mdh's Avatar
    Join Date
    Aug 2007
    Posts
    4,802

    Default

    I think I do, thanks to someone who has a deep history! The subnet list is in some ways live, and in some ways, a historical reference. Spyware sites may still own every IP address in a block that is listed on the subnet list, but other legitimate sites may now be in a listed block as well. We cannot block a legitimate site because of this, so the known sites are blocked by URL. I hope this helps. It has provided a basis for learning for more than one of us!

  7. #7
    Administrator gotkimchi's Avatar
    Join Date
    Jan 2007
    Location
    Bay Area
    Posts
    2,109

    Default

    katabroc, the subnets do not get blocked, however they do get logged. As for the doubleclick ads and such, they do get blocked and logged by our Spyware blocker, since they belong in the cookie list. There are non published spyware URL filters inside the Untangle, working behind the scenes.
    to be understood, you must first understand.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com

  8. #8
    Newbie
    Join Date
    Sep 2007
    Location
    Brazil
    Posts
    4

    Default

    Hmm, now I got it. I think Im goin to block the rest of them with the firewall.
    Thanks for the help guys!

  9. #9
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,691

    Default

    gotkimchi is correct, they are only logged and in the report each access is reported under 'suspicious clients'

    the goal of the subnet list is to detect suspicious behavior.

    many many moons ago we had a 'block' checkbox for each subnet and if the user turned it on they were overwhelmed by false positives. the problem is that those subnets are suspected to host spyware/adware related servers, but blocking them entirely creates more problems than good.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2