Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

The Sleaze Still Found Its Way Through

Untangle's test of five filtering vendors results in lots of porn sites that were missed and many false positives

Apr 09, 2008 | 12:20 PM

By Terry Sweeney
DarkReading

SAN FRANCISCO -- RSA 2008 Conference -- Fortinet emerged as the winner of an event that was part independent product testing, part porn-filter bakeoff.

Wednesday's "Deep Throat Fight Club" event, sponsored by Untangle, pitted five different vendors against one another to filter out the naughty, the explicit, and the grossly anatomical. (See 'Fight Club' Aims to Test Pornography Filters.) In addition to Fortinet, the comparison testing included Barracuda, SonicWall, Watchguard, and WebSense. ScanSafe was part of the original lineup of vendors, but as a hosted solution, the vendor couldn't reconfigure properly in time for the test, the organizers said.

Untangle undertook the test because its own customers complained that products in place were missing sites and that there were too many ways to circumvent the filters. Access to potentially objectionable sites creates legal, moral, and even security issues, since porn sites are increasingly used as vehicles for the propagation of all kinds of malware, the organization said. The event was also a follow-on to a similar antivirus test last summer. (See Antivirus Tools Underperform When Tested in LinuxWorld 'Fight Club'.)

Untangle had each filter scan some 5,000 URLs, using key words and phrases like "nudism," "pornography," "adult/mature content," "intimate apparel/swimsuit," and "not sex education." Each filter was then graded for the percentage of sites correctly blocked, the percentage of sites it missed, and the number of false positives.

Untangle was also careful to emphasize what its testing did not cover -- like performance and speed, IP filtering ability, and other categories like proxies. It also didn't examine or compare advanced features like SSL scanning or safe searches, according to Dirk Morris, CTO and co-founder of Untangle.

Fortinet came out on top, having correctly identified 98 percent of the porn sites in the sample; Barracuda posted the least impressive results with 94 percent. Watchguard and WebSense tied right behind Fortinet; SonicWall was next, followed by Barracuda. Of the five vendors, SonicWall had the most false positives, while Barracuda missed the greatest number of porn sites in its filtering.

Untangle representatives said they were surprised by the number of false positives across the board, and Morris used the event to remind customers to be sure to evaluate such content filters on a broad set of criteria, including price, packaging, and support.

"All products not only missed porn but suffered from false positives, which can be costly to businesses using web filters," Morris said, in a statement. "For some businesses these will make great solutions, but for businesses and schools expecting to block all porn this approach won't cover it all."

The models tested include Barracuda's Web Filter 210 with 3.2.1.021 (2008-01-18) firmware and 1.0.676 (2008-04-08) database; Fortinet's 50A with 3.00-b0662 (MR6 Patch 1) firmware; SonicWall's Pro1260 with SonicOS Enhanced 3.2.3.0-6e; Watchguard's x20e, with build 10.0.2 - Mar 1 2008 and 171410 firmware; and WebSense Express 1.0 with build 20070611_5114 and database 23020 (2008-04-08).

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Barracuda Networks Inc.
  • Fortinet Inc.
  • ScanSafe
  • SonicWall Inc. (Nasdaq: SNWL)
  • Untangle Inc.
  • WatchGuard Technologies Inc. (Nasdaq: WGRD)
  • Websense Inc. (Nasdaq: WBSN)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)