- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Anti-Bot is not working as expected
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anti-Bot is not working as expected
Hi everyone!
I'm do testing Anti-Bot software blade in R80.30 and found something that looks like does not work as expected.
The Security Gateway is able to block definitely with Medium Confidence but if High Confidence does not work and the site test is bypassed, please see screenshots and explanations below
Here are the URLs that I used for Anti-Bot test purpose
https://www.threat-cloud.com/test/files/LowConfidenceBot.html
https://www.threat-cloud.com/test/files/MediumConfidenceBot.html
https://www.threat-cloud.com/test/files/HighConfidenceBot.html
http://sc1.checkpoint.com/za/images/threatwiki/pages/TestAntiBotBlade.html
1st screenshot.
I have already enabled and configured profile on Activation Mode, both High and Medium confidence are Prevented, only Low confidence will be detected.
2.nd screenshot.
Test Anti-Bot with High Confidence by connecting to https://www.threat-cloud.com/test/files/HighConfidenceBot.html
( found nothing blocking from the gateway and any logs ) The user could access the site.
3rd screenshot.
Test Anti-Bot with High Confidence by connecting to https://www.threat-cloud.com/test/files/MediumConfidenceBot.html
The Gateway was able to block this site definitely as expected due to this site is detected as a Medium Confidence level.
4th screenshot.
Test Anti-Bot with High Confidence by connecting to https://www.threat-cloud.com/test/files/LowConfidenceBot.html
The Gateway was able to detect this site definitely as expected due to this site is detected as a Low Confidence level.
5th screenshot,
Test Anti-Bot with High Confidence by connecting to http://sc1.checkpoint.com/za/images/threatwiki/pages/TestAntiBotBlade.html
The Gateway wasn't able to block this site as expected. And from the logs found it appears to redirect an action
My question is why does the security gateway is not able to block the site https://www.threat-cloud.com/test/files/HighConfidenceBot.html and http://sc1.checkpoint.com/za/images/threatwiki/pages/TestAntiBotBlade.html?
Anyone has any ideas on this.
Really appreciate every comment.
Regards,
Sarm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some of the URLs in question are generally used to test / trigger Endpoint (Sandblast Agent) are you seeing different behavior on other gateway versions?
Another useful tool that you may already be familiar with is CheckMe.
Regards,
Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Chris,
Thank you for comment.
As this is the latest version and I think it should be able to block as expected.
I had ever tested this prior R80.30 such as R80.10/R80.20 for example if I recall correctly they were blocked in those versions.
However, I also do a test on SandBlast Mobile Agent but they are not getting blocked as well.
Regards,
Sarm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Sarm,
Why do you think it is expected? The URLs are for Endpoint Security testing (Endpoint Complete / SandBlast Agent).
Consider the scenario that if the Gateway were to block them it would be difficult to test the Endpoint.
Regards,
Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Chris,
Thanks for a quick reply.
I'm probably wrong if some of URLs are only supported for Endpoint Security testing.
But if we consider the link Test Anti-Bot (http://sc1.checkpoint.com/za/images/threatwiki/pages/TestAntiBotBlade.html) from Check Point ThreatWiki this should work, right? But it does not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for clarifying, will confirm the status of the ThreatWiki link in particular and revert.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Otherwise, please ensure that Test Threat Emulation link works also because it just has only Test Anti-Virus link works
Thank you in advance.
Regards,
Sarm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Lab Scenario 1. All Anti-bot tests triggered (note the Protection Name & Resource).
Gateway: R80.20
Browser: IE11
Will follow-up with R80.30 confirmation as time permits.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've found that Firefox 68.0.1 and Chrome 76.0.3809.100 on Mac do not get the UserCheck page when using the Antibot test pages, but Safari does as does IE on Windows. The threat-cloud tests don't seem to trigger it with any browser on Mac (going through 80.30 gateways).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Sarm,
I noticed http://sc1.checkpoint.com/za/images/threatwiki/pages/TestAntiBotBlade.html is redirected to
https://sc1.checkpoint.com/za/images/threatwiki/pages/TestAntiBotBlade.html
Can you try the following? In HTTPS inspection disable Bypass HTTPS inspection of well-known update services
sc1.checkpoint.com is a Check Point software update service
Regards,
marioz
