Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets a reset page.

Reply
L1 Bithead

Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets a reset page.

When you go directly to "shodan.io", which is categorized as a hacking site, the palo will block that URL. When searching thru google for that site, then click on it, a reset page is sent, need to understand why? Is it considered a "threat" if google makes the request? so the threat settings would be used instead of the URL Filtering Security settings? Would Severity settings come into play?

L1 Bithead

Re: Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets

Going directly to the site from my browser the request uses port 80(web page blocked), when using google search the request uses port 443 and I receive "This site cannot be reached" "The connection was reset". 

L5 Sessionator

Re: Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets

Hey @tstores31

 

You were pretty much on the right track with what you said. When you go to "shodan.io" it uses HTTP. The firewall can do a "man in the middle attack" on this HTTP session and present the URL block page.

 

On the Google Search result for shodan.io, the URL is https://. Without SSL decryption, the firewall cannot do a MiTM attack on the SSL site to present the block page, however access to the site can still be blocked as per your URL filtering configuration.

 

To conclude, if you want to present block pages for SSL sites - you will need to configure SSL decryption.

 

Cheers,

Luke.

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!