Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all articles
Browse latest Browse all 3822

How is this executable getting through the HTTP filter?

$
0
0

ISA 2006

I block all users from downloading executable content. Our organization is small enough that I can handle any download request.

I have an Internet access rule that allows HTTP and HTTPS. The HTTP filter is configured to Block responses containing Windows executable content, and I have .exe as a prohibited extension. It has worked great for years.

Today I found that a user had downloaded an executable from Xerox eConcierge. It's just an update for the Supplies Assistant, not a problem. When I checked the logs to see how it got through, it didn't show up. I tried downloading it from a test machine, while monitoring ISA, and again it comes through unscathed. The site uses jsp and it seems it can initiate the download without using HTTP. Does the HTTP filter not work on secure connections? Is there a way to block executables coming in this way? This is the page with the download button:

https://www.econciergetools.com/customerportal.jsp?pkey=i7qB9b5aIVjGNTsvB1VANA%3D%3D&show=1&locale=en_US

Any help with this would be greatly appreciated.


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>