The destination port 443 is well-known and used by attackers to evade detection.
That's some top-notch insight there, Palo Alto. Thanks for the context.
Discussion
The destination port 443 is well-known and used by attackers to evade detection.
That's some top-notch insight there, Palo Alto. Thanks for the context.
@cR0w Block all 443 traffic! (and 53 while we're at it)
@catsalad @cR0w Years back I was pentesting a state government agency and they were so proud of their Sophos with 'advanced heuristics.'
Admittedly it did finally notice something was wrong about my port 443 HTTPS reverse shells.
So Sophos sitewide blocked every computer from using port 443 for anything. I shrugged and watched my backup shell ports over 80 come online.
Guess what was the only port usable to manage Sophos and dismiss the block or see what caused it? 443 😅
So agency IT had to drag a monitor, keyboard, and mouse to the server in the datacenter to resolve. The kicker? The log messages only had endpoint information and did not point to my laptop at all. 🤣
@cR0w Welk known? I thought the S in https stood for Secret?