Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blog: Could Sophos Antivirus Web Protection cause a privacy concern for your org.?

https://labs.portcullis.co.uk/blog/could-sophos-antivirus-web-protection-cause-a-privacy-concern-for-your-organisation/

The blog post above looks at Endpoint Web Protection with the http based SXL lookup and returned values.  Similar data appears available via DNS based SXL lookups but I'm not sure what, if anything, uses the DNS mechanism.

"tr a-z n-za-m" works for ROT13 on lowercase and works on the Sophos UTM.

A previous thread touched on some potential privacy/disclosure concerns https://community.sophos.com/products/unified-threat-management/astaroorg/f/53/t/33654 other threads may exist.

Further, could a sufficiently interested/malicious actor spoof/manipulate responses to potentially alter web policy enforcement?  According to my tests: Yes.


This thread was automatically locked due to age.
Parents Reply
  • Haa sorry, i've been simply saying that i do not think that ROT13 is still used to transfer the target URL to sophos backend anymore. i've done a quick analysis localy with web protection on and it seems DNS queries are sent differently now (using different cipher i'd say). Is this making things safer toward our privacy i do not know...
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?