URL Filtering

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

URL Filtering

L1 Bithead

http://shodan.io/ URL is categorized as hacking website.

Can someone advise as internal users want access to it?

1 accepted solution

Accepted Solutions

Yes, it is a hacking website. 

you can check it here: https://urlfiltering.paloaltonetworks.com/query/

Himani Singh

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

Checked reputation of this url and not seeing any poor reputation of it. Some of the sites are categorizing it under internet and info.

 

https://talosintelligence.com/reputation_center/lookup?search=shodan.io

https://www.brightcloud.com/tools/url-ip-lookup.php

 

M

L4 Transporter

Hello Fidele,

 

I understand that you want to access 'shodan.io' and it was blocked as a hacking site. There are a couple of ways.

(a) you can override your URL filtering object and allow hacking sites.

(b) Depending on the PAN-OS, you can add one site in exception as a white list

(c) you can create a custom URL object and allow it.

(d) If you only want to allow for one user, you can create a policy based on the user, and URL 

some useful documents.

https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/url-filtering/url-filtering-concepts/url-c...

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/url-filtering/url-filtering-concepts/block...

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CltmCAC

 

Thanks

Himani

 

Himani Singh

Yes this can be done or else add object as fqdn "shodan.io" and allow it in policy. But it will allow only 'shodan.io' but not *.shodan.io.

M

Thank you for response. Actually before i do anything, i d like to know if indeed it s hacking website as PaloAlto Firewall categorizes it. I am running PAN-OS 8.1.10

 

Its not specific to PAN version. On my firewall (running on 9.0.3) also getting categorized under hacking site. I checked on few sites and reputation of this url is not listed as poor. Please check my earlier reply.

M

Yes, it is a hacking website. 

you can check it here: https://urlfiltering.paloaltonetworks.com/query/

Himani Singh

Thank you very much for your time and feedback

L0 Member

Visitors on our network can't access to the google drive from web anymore, the application on phone works fine. Anything that I can do about it?

L0 Member

Shodan is not a hacking site per se.  They will port scan all your addresses and will post what vulnerabilities they find.  Obviously, you do not want these advertised as the bad actors will use this database to prey on those who are vulnerable.  It is best to just block these addresses....but there are alot of them.  Some times its a bit of wack-a-mole as well.  There are other companies out there that do the same thing as Shodan (such as Digital Ocean).  

I would like to see Palo-Alto maintain a dynamic list for these shady characters.

 

 

  • 1 accepted solution
  • 9471 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!