This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Should we just turn off IPS all together?

Well looks like with this new update 9.103 we are getting a few different IPS rules that are having issues;

New one this morning pulling my head out, clearing internet cache, excluding the site from web filtering, changing internet browser thinking it was IE, changing computers and applying windows and adobe pdf updates.... no luck!

so anyways this was the IPS issue

Rule ID: 20146 FILE-PDF attempted download of a PDF with embedded PICT image Malware

So now an embedded picture image is malware? nice....

Here is the pdf if anyone wants to have look (just make sure your IPS rule is off)

http://goautomedia.cdn.on.net/goautonews/GoAutoNews_686.pdf

.


This thread was automatically locked due to age.
Parents
  • I just clicked on the link to the PDF file that stealthmatt posted and I'm able to download it just fine. I also have the new update 9.103.

    --------------------------------------------------------------------
    Sophos UTM 9.714-4 - Home User
    Currently testing VM on i3-9100 @ 3.60 GHz
    16 GB RAM
    Dell Optiplex XE
    Intel Core 2 Duo CPU E8600 @ 3.33GHz
    8GB RAM
    --------------------------------------------------------------------

Reply
  • I just clicked on the link to the PDF file that stealthmatt posted and I'm able to download it just fine. I also have the new update 9.103.

    --------------------------------------------------------------------
    Sophos UTM 9.714-4 - Home User
    Currently testing VM on i3-9100 @ 3.60 GHz
    16 GB RAM
    Dell Optiplex XE
    Intel Core 2 Duo CPU E8600 @ 3.33GHz
    8GB RAM
    --------------------------------------------------------------------

Children
No Data