<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hacking URL, direct thru Palo, deny reason &amp;quot;block URL&amp;quot;, via a search thru google, gets a reset page. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236879#M67884</link>
    <description>&lt;P&gt;When you go directly to "shodan.io", which is categorized as a hacking site, the palo will block that URL. When searching thru google for that site, then click on it, a reset page is sent, need to understand why? Is it considered a "threat" if google makes the request? so the threat settings would be used instead of the URL Filtering Security settings? Would Severity settings come into play?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2018 17:50:51 GMT</pubDate>
    <dc:creator>tstores31</dc:creator>
    <dc:date>2018-10-24T17:50:51Z</dc:date>
    <item>
      <title>Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets a reset page.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236879#M67884</link>
      <description>&lt;P&gt;When you go directly to "shodan.io", which is categorized as a hacking site, the palo will block that URL. When searching thru google for that site, then click on it, a reset page is sent, need to understand why? Is it considered a "threat" if google makes the request? so the threat settings would be used instead of the URL Filtering Security settings? Would Severity settings come into play?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 17:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236879#M67884</guid>
      <dc:creator>tstores31</dc:creator>
      <dc:date>2018-10-24T17:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236905#M67885</link>
      <description>&lt;P&gt;Going directly to the site from my browser the request uses port 80(web page blocked), when using google search the request uses port 443 and I receive "This site cannot be reached" "The connection was reset".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 19:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236905#M67885</guid>
      <dc:creator>tstores31</dc:creator>
      <dc:date>2018-10-24T19:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236908#M67886</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47145"&gt;@tstores31&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You were pretty much on the right track with what you said. When you go to "shodan.io" it uses HTTP. The firewall can do a "man in the middle attack" on this HTTP session and present the URL block page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Google Search result for shodan.io, the URL is https://. Without SSL decryption, the firewall cannot do a MiTM attack on the SSL site to present the block page, however access to the site can still be blocked as per your URL filtering configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To conclude, if you want to present block pages for SSL sites - you will need to configure SSL decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 19:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/236908#M67886</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-24T19:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets a reset page.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/417203#M93526</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172278"&gt;@pal7mentor&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp; says you should be able to enable block page for encrypted traffic even without SSL decryption&lt;/P&gt;&lt;P&gt;Details in the following link - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0" target="_blank"&gt;How to Serve a URL Response Page Over an HTTPS Session Without ... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 05:51:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hacking-url-direct-thru-palo-deny-reason-quot-block-url-quot-via/m-p/417203#M93526</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-07-06T05:51:05Z</dc:date>
    </item>
  </channel>
</rss>

