View Single Post
Old 04-04-2008, 21:21   #2326
SMHarman
Inactive
 
Join Date: Jun 2003
Services: Cablevision
Posts: 8,305
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
Re: Virgin Media Phorm Webwise Adverts [Updated: See Post No. 1, 77, 102 & 797]

Quote:
Originally Posted by kt88man View Post
Richard Clayton (FIPR) has just released his write up of Webwise/Phorm:

http://www.lightbluetouchpaper.org/2...ebwise-system/

Detailed technical:

http://www.cl.cam.ac.uk/~rnc1/080404phorm.pdf
3 - The L7 switch ignores non 80 traffic (as it is currently programmed, they could reprogram it at any time)
? Is this why the transparent proxys have been killed off, can we all browse on port 8080 instead to avoid this or will phorm just add that port to the switch rules and the 307 redirects ?

4 - An L7 switch also understands every other TCP/IP protocol so changes to the programming could again mean it could read data on any other port.

35 - inspects only text/html, but what if other flags were put in there instead. It will start inspecting them

36 - again whitelists - change the content of the whitelist and you change what is profiled

37 - again whitelist of exclude 'basic auth' - take it away and you can profile it.

38 - Webmail. Well my webmail is on port 2096 and 2083 of my server so I guess it is not included in the 'more than 25 sites'. Maybe it will be covered by the 'basic auth' or the 'https' but Phorm can take them away.

43 - So you could probably block Phorm by putting an exclusion on robots.txt but phorm won't tell us what they refer to their bot as, sounds like it will impersonate googlebot (is that allowed).

49 - So they designed the software to ignore zip codes but not post codes, or canadian post codes or or or.

86a - If they can't tell this how can they give feedback to their advertisers?
SMHarman is offline