Defeating WebSense

I have two laptops (one personal, one work) and one home desktop PC. It would be nice to have some files synchronized between them all. I already use Mozy to back up my personal laptop, but that doesn’t address synchronization issues.

I wanted a web-based solution (similar to Mozy), so I did a quick Google search to see what my options were. The first item in the list was FolderShare (by Microsoft), so I figured I’d check it out. I went to http://www.foldershare.com Here’s what I saw:

Blocked by WebSense

Damn… Well, not a big deal. Since I’m a sys admin here, I can just configure WebSense to ignore requests from my IP address. Before I did that, I tried changing the URL to https://www.foldershare.com.

And guess what? It worked!

Apparently, WebSense sees an SSL site as different from the non-SSL site. I have no idea if this is an oversight just for FolderShare, or some weird configuration thing here, or something related to the version of WebSense we’re running… but it is interesting to know that such a simple workaround exists.

Anyway, I’ll be testing FolderShare now — and will blog about that in due time.

Bookmark and Share

Popularity: 21% [?]

Related Posts

  • No related posts

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.

-- Albert Einstein

Comments 3

  1. Manotas wrote:

    Hi,
    I tried but it didn’t work at my work…

    Just to let you know

    Cheers….

    Posted 23 Oct 2007 at 5:30 am
  2. brian wrote:

    I’m not surprised — it certainly wouldn’t work in all situations, but it’s worth the try… :)

    Posted 23 Oct 2007 at 7:01 am
  3. Robert wrote:

    I’ve been fighting this very issue myself, except on sites I don’t want the users to get to. Per Websense technical support, this is the case for all the different ‘integration’ options they have. UNLESS you have a proxy server.
    The problem stems from the fact that the SSL packet is encrypted and so cannot ’see’ what the URL is only the IP address - which may or may not be in a permitted (or blocked) category.

    But it is a huge security hole……

    Posted 02 Nov 2007 at 5:09 pm

Post a Comment

Your email is never published nor shared. Required fields are marked *