<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pandora Streaming Traffic intermittently 'redirected' as Malicous in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18379#M3306</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TAC was unable to adequately solve the problem.&amp;nbsp; &amp;nbsp;Instead workarounds had to be put in place, some in my opinion to broad in nature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Jul 2018 16:07:41 GMT</pubDate>
    <dc:creator>Daniel_Morin</dc:creator>
    <dc:date>2018-07-27T16:07:41Z</dc:date>
    <item>
      <title>Pandora Streaming Traffic intermittently 'redirected' as Malicous</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18377#M3304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We just recently received complaints that in the last 2 weeks streaming Pandora audio on our guest network intermittently freezes.&amp;nbsp; &amp;nbsp;Restarting the Pandora session fixes the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our guest WiFi network has a separate VLAN and internet connection than all of our other traffic.&lt;/P&gt;&lt;P&gt;We have a rule in our Application policy to block access to malicious sites originating from our guest VLANs, based on the Checkpoint pre-defined application category.&lt;/P&gt;&lt;P&gt;What we found in our logs was that intermittently Pandora traffic is 'redirected', being associated with the Phishing category.&amp;nbsp; Most of such entries are flagging URL similar to&amp;nbsp;&lt;A class="link-titled" href="http://cont-4.p-cdn.us/images/public/amz/8/4/2/7/800027248_500W_500H.jpg" title="http://cont-4.p-cdn.us/images/public/amz/8/4/2/7/800027248_500W_500H.jpg"&gt;http://cont-4.p-cdn.us/images/public/amz/8/4/2/7/800027248_500W_500H.jpg&lt;/A&gt;&amp;nbsp;as phishing, where&amp;nbsp;&lt;A href="http://cont-4.p-cdn.us/images/public/amz/8/4/2/7/800027248_500W_500H.jpg" style="color: #2989c5; text-decoration: underline;" title="http://cont-4.p-cdn.us/images/public/amz/8/4/2/7/800027248_500W_500H.jpg"&gt;cont-4.p-cdn.us&lt;/A&gt;&amp;nbsp;resolves to 208.85.44.21, which has PTR of&amp;nbsp;mediaserver-cont-dc6-1-v4.pandora.com so it is one of Pandora's IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint Support has had us add a rule above the Guest - Block Malicious Sites to specifically allow traffic classified as Pandora, but still we see redirects I just described.&amp;nbsp; We haven't received any further complaints though since having added the rule Support had suggested but these redirect entries associated with Pandora IPs I still see in the Block rule troubles me.&lt;/P&gt;&lt;P&gt;Looking further at the logs, I'm seeing log entries associated with the Block rule within 2 hours after having added the Allow Pandora rule where the log entry shows the category as Pandora, usrcheck message claiming access to&amp;nbsp;b.scorecardresearch.com is blocked by our security policy.&amp;nbsp; &amp;nbsp;Since&amp;nbsp;b.scorecardresearch.com resolves to 96.16.98.73, why was it associated with Pandora traffic destined to&amp;nbsp;mediaserver-ch1-t3-2-v4.pandora.com (208.85.44.28)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone else seeing Pandora traffic affected as potentially malicious Phishing traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 13:52:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18377#M3304</guid>
      <dc:creator>Daniel_Morin</dc:creator>
      <dc:date>2018-04-26T13:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Pandora Streaming Traffic intermittently 'redirected' as Malicous</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18378#M3305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's possible we may need to see some traffic captures of the relevant traffic to understand what's going on.&lt;/P&gt;&lt;P&gt;They can be provided through your TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 16:31:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18378#M3305</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-26T16:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Pandora Streaming Traffic intermittently 'redirected' as Malicous</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18379#M3306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TAC was unable to adequately solve the problem.&amp;nbsp; &amp;nbsp;Instead workarounds had to be put in place, some in my opinion to broad in nature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2018 16:07:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Pandora-Streaming-Traffic-intermittently-redirected-as-Malicous/m-p/18379#M3306</guid>
      <dc:creator>Daniel_Morin</dc:creator>
      <dc:date>2018-07-27T16:07:41Z</dc:date>
    </item>
  </channel>
</rss>

