Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.
XG 19.5 GA 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
16GB Memory | 500GB SSD HDD | GB Ethernet x5
Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.
Hi,
does anyone know if the Webfilter is vulnerable when doing HTTPS scan?
We use UTM 9.211 and the OpenSSL library is 1.0.1j (vulnerable).
(e.g. UTM version 9.308 uses OpenSSL 1.0.1k and so I guess the web proxy is secure, except if it's using another SSL library).
The question is: when doing HTTPS scan, does the UTM
a) pass through the cipher list from the browser or
b) does it send its own list (containing export grade ciphers)?
In case of b), the SSL connection between server and UTM could be vulnerable even if the browser is updated and has a secure connection to the UTM.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow