View Full Version : Bypass DNS blocking?
Acuracy
January 16th, 2009, 12:42 PM
Anyone know how to bypass DNS blocking? I know theres a site you can go to that you enter the website you want to go to on it and it tricks the DNS somehow...?
Semi Jew
January 16th, 2009, 12:43 PM
yes, but doing it through DNS would disconnect you from your servers. they use internal dns there.
03scgt
January 16th, 2009, 12:43 PM
http://www.browser9.com/
if that doesnt work google proxy server and you can find one that will
Semi Jew
January 16th, 2009, 12:47 PM
try the proxy thing, but im pretty sure the cisco there blocks any internet activity using proxy servers.
Acuracy
January 16th, 2009, 12:48 PM
http://www.browser9.com/
if that doesnt work google proxy server and you can find one that will
lol I got this:
Trend Micro URL Filter
Trend Micro URL Filter has blocked the requested Web URL by Credibility Level.
URL: http://www.browser9.com/
Category: Hacking / Proxy Avoidance
Credibility Level: Dangerous
Copyright (C) 2008 Trend Micro Inc. (http://www.trendmicro.com/)
What's this google proxy?
Acuracy
January 16th, 2009, 12:49 PM
I got this from the google proxy:
Site blocked. translate.google.com is not allowed on this network. If you believe that this domain should be allowed, please send email to 'Computer Requests'
This site was categorized (http://www.opendns.com/community/domaintagging/categories) as:
Proxy/Anonymizer
Questions? (http://block.opendns.com/controller.php?url=8583667984776685701572808072777 01568807816858366798477668570646832737730707907776 67972816674833070790624367079078630738585812716168 88888159080868586677015688078160786847230344576438 37373764349504688734179268046484089425551362469902 379917534&ablock=&view=blocked_domain&ref=#) Not properly categorized? (http://block.opendns.com/controller.php?url=8583667984776685701572808072777 01568807816858366798477668570646832737730707907776 67972816674833070790624367079078630738585812716168 88888159080868586677015688078160786847230344576438 37373764349504688734179268046484089425551362469902 379917534&ablock=&view=blocked_domain&ref=#)
GRR...
03scgt
January 16th, 2009, 12:50 PM
google has a ton of different proxy servers.im just saying type in proxy server to google and youll find your answer
Semi Jew
January 16th, 2009, 12:54 PM
stop James. The first block message you got was logged in the trend antivirus console, and the second by Cisco websense.
Acuracy
January 16th, 2009, 12:56 PM
Eww... ok thanks.
03scgt
January 16th, 2009, 12:57 PM
lol now they know what your trying to do because it sent them a nice message
Acuracy
January 16th, 2009, 12:59 PM
haha yea, well if it just goes to Bill i'll be able to tell him I was just testing something. If it goes to our CFO Brian well... yea.
Semi Jew
January 16th, 2009, 01:00 PM
they paid $6000 for that router and software... if you were able to defeat it that would really suck.
Acuracy
January 16th, 2009, 01:02 PM
lol, you probably can it's just a matter of time and trial/error. I just can't do it again if it's logging it!
STiDriven
January 16th, 2009, 03:35 PM
Burn The Fucker Down!
Sloww
January 16th, 2009, 03:53 PM
try unblockmyspace.com, http://anonymouse.org/anonwww.html, http://www.cgi-proxy.net/
probably all going to be blocked though
Acuracy
January 16th, 2009, 03:56 PM
Naa, I can explain away a couple of them as a quick test but if I keep doing it i'll get pwnd.
titter
January 17th, 2009, 11:37 PM
It can be done pretty easily if you have access to cmd, and the at command is not blocked. There are many ways around what your company is doing ... how much local system access do you have? What type of setup are you on? Do you login to a company domain? If it is strictly Cisco Websense, you can bypass it very easily with enough local system access.
Acuracy
January 18th, 2009, 08:46 PM
I can get basically as much access as i'd want but as i said i'm not gonna keep fucking with it. I was just curious and wanted to try real quick but it's not worth getting fired over.
wiszmaster
January 18th, 2009, 10:25 PM
lol ... I use blacklisted URLs, Domains & RBL's in our content filter as well. Always pissed the hell out of people when they couldn't access their beloved sites.
m_prelude
February 1st, 2009, 09:46 PM
A trick I found in Lee county school's new scanner. Not sure if it works otherwise, Or if my explanation is even correct - But it's all I can come up with.
The scanner listens on port 80 (Standard HTTP)... Before it allows you to load a page it scans the content and decides whether or not it's appropriate.
Simply adding a S to http (to make it https://) moves it to ssl. SSL is on port 443, thus allowing you to access any site that has SSL enabled. This is how I manage to check my gmail from school.
Getting around basic things, Depending on the ruleset is exactly what you said: trial and error. I usually start with trying to use a Socks 4/5 Proxy instead of a web proxy. From there, move to a SSH tunnel (if you have SSH running on a oddball port, it isn't usually blocked) and keep trying.
Watch out for logs though, They can get you into some shit.
Few other things:
You say DNS blocking... So is it only blocking the domain? Can you ping the website and go to it by IP?
Another trick which i don't quite remember in its entirety is something I read in 2600... It involved converting the IP address to binary and then into some other form, I can't remember what. That would allow you to access most sites - Even myspace. I'll look into that again.
Acuracy
February 1st, 2009, 10:59 PM
Eh, I don't work there anymore anyway lol.
titter
February 1st, 2009, 11:37 PM
Eh, I don't work there anymore anyway lol.
What happened?
Acuracy
February 2nd, 2009, 01:26 AM
I quit because I found a better job.
titter
February 2nd, 2009, 01:51 AM
I quit because I found a better job.
:SolidStraight:
vBulletin® v3.8.2, Copyright ©2000-2012, Jelsoft Enterprises Ltd.