Wednesday, April 1, 2015

Really Cisco???

Question - how much is Cisco charging you for the renewal of your IronPort S Class Appliance (web gateway)?  And... do you feel the Senderbase Reputation System, and the associated URL Database, is keeping your IT Assets secure?  We at ESPO would argue that you consider the following attack emanating out of Hong Kong:

Chinabest-ent.com is leveraging an IP Address currently owned by Network Infinity based out of Hong Kong.  If you are a Cisco customer, your users currently have no problem accessing this site as it's currently classified with a Neutral Web Reputation:







However, as proven below, the Websense ACE Technology has identified that the site is hosting malicious content:



More importantly, the malware then attempts to POST data out to a site in Russia:


In summary, we've stated many times how your Security spend could/should be reduced by squeezing your AV Vendors; however, it may be time to redirect your Cisco renewal towards Websense too.  :-)

2 comments:

  1. This blog is really helpful regarding all educational knowledge I earned. It covered a great area of subject which can assist a lot of needy people. Everything mentioned here is clear and very useful. Nutanix Xpress 3Node

    ReplyDelete
  2. The approach of writer is virtually commendable. The manner he makes use of his innovative imaginative and prescient to transform into terms and permit us to suppose in a one of a kind way too. totally unforgettable revel in after studying this blog. Cisco SG500

    ReplyDelete