Educause Security Discussion mailing list archives
Re: Blocking URLs
From: "Barton, Robert" <bartonrt () LEWISU EDU>
Date: Fri, 31 Jul 2015 16:53:52 +0000
Research if you can use a FQDN or domain name in the rule. This will solve for a dynamic IP and possible get the larger group of servers. This still is not the best solution, but may ease the pain. Can you do the blocking of the sights at your proxy server, if you have one? This will not stop C&C communications like a firewall rule, but would stop the users from hitting websites that are phishing. Robert W. Barton Director of Information Security Lewis University One University Parkway Romeoville, IL 60446-2200 815-836-5663 From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Chris Green Sent: Friday, July 31, 2015 11:47 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] Blocking URLs All, We are looking for a cost effective solution to prevent users from accessing sites when they fall for phishing attempts. Right now we are blocking IPs for those sites in our firewall, but this is not a great solution for us as we don't want to load up our firewall with these types of rules, and the majority of these sites use dynamic IPs, so it's a temporary fix at best. I wanted to see if anyone had come up with a solution for this dilemma that doesn't involve dropping six figures on an application firewall. Thanks, -C. Chris Green Information Security Officer University of Texas at Tyler This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, notify us immediately by telephone at (815)-836-5950 and (i) destroy this message if a facsimile or (ii) delete this message immediately if this is an electronic communication. Thank you.
Current thread:
- Blocking URLs Chris Green (Jul 31)
- Re: Blocking URLs Barton, Robert (Jul 31)
- Re: Blocking URLs Bob Bayn (Jul 31)
- Re: Blocking URLs Pratt, Benjamin E. (Jul 31)
- Re: Blocking URLs Andre DiMino (Jul 31)
- Re: Blocking URLs Chris Green (Jul 31)
- Re: Blocking URLs Tevlin, Dave (Jul 31)
- Re: Blocking URLs randy (Jul 31)
- Re: Blocking URLs McClenon, Brady (Jul 31)
- Re: Blocking URLs Shamblin, Quinn (Aug 12)