Hello!
It's simple business task: block all JS inside ZIP (mail protection).
It is really a new epidemic - JS downloaders that run encryption-virus. Endpoint AV don't help..., because it's 'legal' encryption.
JS looks like DOC, and users just click on it, especially in targeted attack.
It´s unbelievable Sophos has not covered this by now. It´s really unbelievable.
Hello Emily,
could please explain, why this setting "MIME Blocking Inspects HTTP Body" is necessary and in which cases it is necessary and recommend? Are there any disadvantages? Afaik this option is disabled by default. But why, when you know, that this is necessary to block by mimetype within archives?
And the next question, where is the documentation about that? I would suggest a honest article in the knowledgebase about the current problems with blocking files and also with tips about the best settings.
Best Regards
Sebastian
Hello Joerg,
did you already take a look into this? Pretty interesting.
http://noxxi.de/research/sophos-utm-webprotection-bypass2.html
I am really missing the documentation about this "weaknesses" in the utm. I think its no good advertisement to get to know about this information on different websites (I also created an own thread for this), but not on the official sophos site. In this case im pretty disappointed about the way sophos cares about this... To put that into relation to other arguments: When someone is talking about feature requests for certain things, I´ve often read, that this or that feature will not be implemented for security reason, because it doesn´t fit into the product philosphy. I think theres somethong wrong in here...
Regards
Sebastian
Sebastian,
yeah - as I said - i find that unbelievable!
I can tell you what I am doing: I do SMTP- and HTTP-chaining and put another good Multi-Engine AV Product behind our UTM. That catches all the configured attachments the UTM would let pass.
Sophos HAS TO come around with a solution! This is no rocket science! The situation now - with SMTP only MIME types filtering by extensions within archives - to be honest - that makes me really sad.
Thanks
Joerg