This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Intercept-x blocking Malware site in http but not https, XG firewall does.

Hi,

on our XG I found this logs frequently

;Time;Log subtype;Username;Src IP;Dst IP;Category;URL;Bytes sent;Referrer;Message ID;Policy ID;;
Web filter;27.01.2021 12:28;Denied;xxx;xxx;35.201.108.94;Spyware & Malware;https://logs.spilgames.com/lg/pb/1/ut/ ;0;https://www.jetztspielen.de/spiel/meister-der-blocke;16002;2;;
Web filter;27.01.2021 12:28;Denied;xxx;xxx;35.201.108.94;Spyware & Malware;https://logs.spilgames.com/lg/pb/1/ut/ ;0;https://www.jetztspielen.de/spiel/meister-der-blocke;16002;2;;
Web filter;27.01.2021 12:28;Denied;xxx;xxx;35.201.108.94;Spyware & Malware;https://logs.spilgames.com/lg/pb/1/ut/ ;0;https://www.jetztspielen.de/spiel/meister-der-blocke;16002;2;;
Web filter;27.01.2021 12:28;Denied;xxx;xxx;35.201.108.94;Spyware & Malware;https://logs.spilgames.com/lg/pb/1/ut/ ;0;https://www.jetztspielen.de/spiel/meister-der-blocke;16002;2;;

Like just seen last week with a different URL, Intercept-X Client does not block this site:

hxxps://logs.spilgames.com/lg/pb/1/ut/

It's only blocked when opening with http, not https - and the category is Hacking then, not Malware.

I get a 404 from the webserver when using https because there is no content but this is not an intercept-x block.

I checked the URL again on our XG and it says Spyware & Malware

Why is the super-hyped Intercept-X not doing what others do?



This thread was automatically locked due to age.
Parents Reply
  • Hi,

     yes I have learned that. But Intercept does not block it as stated above - I get the 404 from the webserver.

    I get some sort of SSL error if Intercept-X would do what it's paid for.

    Not even sure if it is or was a malware site? Could imagine it has been used as source for pishing.

    But If some Sophos products (XG) say, this is a bad site, and some (Intercept-X) don't it makes me feel fooled.

    Or if Intercept-X says, this site is bad on http and good on https thats just a joke.

Children
No Data