This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bypassing Malware Scanning in Sophos UTM with HTTP compression

Hi all,

Did anyone saw this post?
Bypassing Malware Scanning in Sophos UTM Web Protection (patched)

Any commments? is it that simple to avoid IDS/Snort/Suricata??
Dubious HTTP II - Unusual HTTP Content-Encodings

Thanks for your inputs,
regards,
m.


This thread was automatically locked due to age.
  • Since this is patched in both 9.2 and 9.3, you're not exposed even if the malware is not caught by Snort.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA