[RESOLVED] ABE Nat Pinning Warning
Posted: Fri May 04, 2012 10:45 pm
Hello,
I recently added the ABE rule for Nat Pinning (Thanks to Tom T).
# NAT Pinning blockage (blocks outbound HTTP traffic to unlikely ports)
Site ^https?://[^/]+:[0-35-7]
Deny
That rule triggered a warning on a couple of links today, and I was wondering if somebody could please verify if it was protecting me from an actual attack, or was it possibly a false positive.
Here's one example:
Go here -http://www.uploadc.com/11qvmd48tufm/Hirokin.2011.DVDRip
On the left, click the button "Slow Access".
On the following page, click the big yellow download button.
On the following page, click the red download button.
You should now get the ABE warning.

Thanks for any help,
RD.
I recently added the ABE rule for Nat Pinning (Thanks to Tom T).
# NAT Pinning blockage (blocks outbound HTTP traffic to unlikely ports)
Site ^https?://[^/]+:[0-35-7]
Deny
That rule triggered a warning on a couple of links today, and I was wondering if somebody could please verify if it was protecting me from an actual attack, or was it possibly a false positive.
Here's one example:
Go here -http://www.uploadc.com/11qvmd48tufm/Hirokin.2011.DVDRip
On the left, click the button "Slow Access".
On the following page, click the big yellow download button.
On the following page, click the red download button.
You should now get the ABE warning.
Thanks for any help,
RD.