Seeing about six of our sites (all running the slightly older 9.408 release) getting APT alerts for ocsp.comodoca.com starting this morning (2017-02-21 ~9 am EST)?
Anyone else seeing this occur?
This thread was automatically locked due to age.
Seeing about six of our sites (all running the slightly older 9.408 release) getting APT alerts for ocsp.comodoca.com starting this morning (2017-02-21 ~9 am EST)?
Anyone else seeing this occur?
yeppers. It's a false positive. This very site is also getting blocked as a site with poor reputation by the SG reputation filter int he http proxy..classic.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
yeppers. It's a false positive. This very site is also getting blocked as a site with poor reputation by the SG reputation filter int he http proxy..classic.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
William Warren said:yeppers. It's a false positive. This very site is also getting blocked as a site with poor reputation by the SG reputation filter int he http proxy..classic.
Far as I know, the websites tab on Filtering Options is not touched by any Firmware or Patterns updates. Anything there is a manual entry by an Admin , it does sound like you have something amiss.
Seems fine now here, too.
If entering the URL with Ac%3D at the end in the browser directly, I no longer geht a Trojan warning, just a Reputation Limit instead.
Just a question aside: Are the most of you downloading the Virus Pattern manually? For maximum security we keep the interval the shortest (15 min) and let the UTM do that automatically. Just curious.