Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Parabol
Contributor

polyfill.io - malicious script embedded in websites. How to handle DNS queries to it?

Hi all,

Over the past month we have seen some of our users sending DNS queries for polyfill.io and cdn.polyfill.io.

Numerous articles such as this this one  report that it has started spreading malicious code to visitors of websites that use this script.

I see that our checkpoint Anti-Virus blade is detecting this as protection - CeptBiro.TC.b726wWvx

The action has been a mix of detect and prevent - do you know why this is? Is there a way to change the action to always prevent? I searched for the protection under IPS protections but could not find it. I show the logs in the attached screenshot.

Thanks!

0 Kudos
1 Reply
John-Haynes
Participant

You'll need to force background classification into hold.  Run the following:

 

cp -v $FWDIR/conf/malware_config $FWDIR/conf/malware_config_ORIGINAL
sed -ie 's/^dns=.*$/dns=hold/' $FWDIR/conf/malware_config

 

Install TP policy after this and everything should be seen as prevent in the logs.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events