Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FakeAv Fakedefrag

Has anyone come up with a successful way of blocking these Fake products getting in past the firewall. Symantec on the desktops discover and block but i would have hoped we could stop these at the firewall. The sites containing the code are always changing but the url for the moment is consistant eg clickbits.org/dfrg/dfrg. Can we get the fortigate to block this in anyway? Thanks
1 REPLY 1
billp
Contributor

I had one of these yesterday with a user. It used a dynamically generated URL that expired after a few minutes so that I couldn' t load the page later to examine the code on my test machine. Agreed -- would definitely like the Fortigate box to catch these.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Labels
Top Kudoed Authors