<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>UTM - Redirection via Arbitrary Host Header Manipulation ?</title><link>https://community.sophos.com/utm-firewall/f/general-discussion/142309/utm---redirection-via-arbitrary-host-header-manipulation</link><description>Hi, 
 
 A customer of ours has had PCIDSS check done and failed, the report came back with the following but not sure what to do. They only have one website behind the firewall, exchange owa. Looking at the details, its referring to the UTM as the Host</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: UTM - Redirection via Arbitrary Host Header Manipulation ?</title><link>https://community.sophos.com/thread/530668?ContentTypeID=1</link><pubDate>Wed, 11 Oct 2023 20:46:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8e700bc0-9263-4bf2-acd7-bfb27dcc16cf</guid><dc:creator>SGICT</dc:creator><description>&lt;p&gt;So this turned out to be a tricky one with no real good outcome as the PCI DSS scan was being done by an external firm and no means to find out what tools they were using to detect this nor were they willing to help.&lt;/p&gt;
&lt;p&gt;This is from Sophos Tech Support so even they didnt know why the scan was picking it up because they remoted in and saw there were no WAF rules in place.&lt;/p&gt;
&lt;p&gt;In a nutshell, disabling WAF was the only way to stop the scan failing - if you are doing this please ensure you are not using WAF.&lt;/p&gt;
&lt;p&gt;So to do this&lt;/p&gt;
&lt;p&gt;SSH into the UTM&lt;/p&gt;
&lt;p&gt;Logon as loginuser&lt;/p&gt;
&lt;p&gt;su root&lt;/p&gt;
&lt;p&gt;cd.. &lt;br /&gt;cd..&lt;br /&gt;cd etc&lt;br /&gt;cd init.d&lt;br /&gt;/var/mdw/scripts/reverseproxy stop&lt;/p&gt;
&lt;p&gt;The command will only stop the service and it&amp;#39;ll restart again when the UTM is next rebooted.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>