URL Filtering

Reply
Highlighted
L1 Bithead

URL Filtering

http://shodan.io/ URL is categorized as hacking website.

Can someone advise as internal users want access to it?


Accepted Solutions
Highlighted
L4 Transporter

Re: URL Filtering

Yes, it is a hacking website. 

you can check it here: https://urlfiltering.paloaltonetworks.com/query/

Himani Singh

View solution in original post


All Replies
Highlighted
L5 Sessionator

Re: URL Filtering

Checked reputation of this url and not seeing any poor reputation of it. Some of the sites are categorizing it under internet and info.

 

https://talosintelligence.com/reputation_center/lookup?search=shodan.io

https://www.brightcloud.com/tools/url-ip-lookup.php

 



Mayur Sutare
Highlighted
L4 Transporter

Re: URL Filtering

Hello Fidele,

 

I understand that you want to access 'shodan.io' and it was blocked as a hacking site. There are a couple of ways.

(a) you can override your URL filtering object and allow hacking sites.

(b) Depending on the PAN-OS, you can add one site in exception as a white list

(c) you can create a custom URL object and allow it.

(d) If you only want to allow for one user, you can create a policy based on the user, and URL 

some useful documents.

https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/url-filtering/url-filtering-concepts/url-c...

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/url-filtering/url-filtering-concepts/block...

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CltmCAC

 

Thanks

Himani

 

Himani Singh
Highlighted
L5 Sessionator

Re: URL Filtering

Yes this can be done or else add object as fqdn "shodan.io" and allow it in policy. But it will allow only 'shodan.io' but not *.shodan.io.



Mayur Sutare
Highlighted
L1 Bithead

Re: URL Filtering

Thank you for response. Actually before i do anything, i d like to know if indeed it s hacking website as PaloAlto Firewall categorizes it. I am running PAN-OS 8.1.10

 

Highlighted
L5 Sessionator

Re: URL Filtering

Its not specific to PAN version. On my firewall (running on 9.0.3) also getting categorized under hacking site. I checked on few sites and reputation of this url is not listed as poor. Please check my earlier reply.



Mayur Sutare
Highlighted
L4 Transporter

Re: URL Filtering

Yes, it is a hacking website. 

you can check it here: https://urlfiltering.paloaltonetworks.com/query/

Himani Singh

View solution in original post

Highlighted
L1 Bithead

Re: URL Filtering

Thank you very much for your time and feedback

Highlighted
L0 Member

Re: URL Filtering

Visitors on our network can't access to the google drive from web anymore, the application on phone works fine. Anything that I can do about it?

Highlighted
L0 Member

Re: URL Filtering

Shodan is not a hacking site per se.  They will port scan all your addresses and will post what vulnerabilities they find.  Obviously, you do not want these advertised as the bad actors will use this database to prey on those who are vulnerable.  It is best to just block these addresses....but there are alot of them.  Some times its a bit of wack-a-mole as well.  There are other companies out there that do the same thing as Shodan (such as Digital Ocean).  

I would like to see Palo-Alto maintain a dynamic list for these shady characters.

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!