Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 18th, 2012, 02:29 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Blocked internet jpg files

I have noticed that when I browse a site, we'll use Bing for an example, that when doing an image search sometimes a .jpg file is blocked. Is this because ESS thinks there is an issue with that actual ,jpg file, or because the domain it is coming from is blacklisted for some other malicious files?
  #2  
Old March 18th, 2012, 02:43 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Blocked internet jpg files

I suspect that Bing thumbnails actually originate from Bing servers. I just did an image search to test and indeed they do. So I don't think it's a domain blacklist issue unless Bing image hosting servers got on the list.

Actually I'm assuming you were even talking about the thumbnails in the first place? =P
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #3  
Old March 18th, 2012, 03:45 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: Blocked internet jpg files

Please post here a screen shot of the alert you're getting.
  #4  
Old March 18th, 2012, 04:25 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: Blocked internet jpg files

This is from the Bing homepage today (3-18-2012). I clicked on the first hotspot.

The red arrow points to where the missing thumbnail would have loaded.
Attached Images
  
  #5  
Old March 19th, 2012, 01:16 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: Blocked internet jpg files

It's beinsure.co.cc that is blocked.
  #6  
Old March 19th, 2012, 07:26 AM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: Blocked internet jpg files

Quote:
Originally Posted by Marcos
It's beinsure.co.cc that is blocked.

So to clarify you are saying that the entire domain is blocked, and not specifically that ,jpg file, correct?
  #7  
Old March 19th, 2012, 08:05 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Blocked internet jpg files

Quote:
Originally Posted by Marcos
It's beinsure.co.cc that is blocked.

But the thumbnail originates from ts3.mm.bing.net as can be seen in the screenshot. Seems like NOD32 is scanning the entire URL instead of just the originating domain, somewhat flawed?
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #8  
Old March 19th, 2012, 08:12 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: Blocked internet jpg files

Quote:
Originally Posted by xxJackxx
So to clarify you are saying that the entire domain is blocked, and not specifically that ,jpg file, correct?
Right, the whole domain is blocked.
  #9  
Old March 19th, 2012, 08:14 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: Blocked internet jpg files

Quote:
Originally Posted by funkydude
Seems like NOD32 is scanning the entire URL instead of just the originating domain, somewhat flawed?
Quite the contrary. Not scanning the whole domain would pose a security risk and might lead to computer infection in case there's a new unrecognized threat at the malicious url that is blocked.
  #10  
Old March 19th, 2012, 08:17 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Blocked internet jpg files

Quote:
Originally Posted by Marcos
Quite the contrary. Not scanning the whole domain would pose a security risk and might lead to computer infection in case there's a new unrecognized threat at the malicious url that is blocked.

From what, a thumbnail? As far as I'm aware there is no threat unless the image is clicked on, at which point you'd be forwarded to the site, at which point NOD32 can prevent the site from loading anyway.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #11  
Old March 19th, 2012, 09:23 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: Blocked internet jpg files

Quote:
Originally Posted by funkydude
From what, a thumbnail? As far as I'm aware there is no threat unless the image is clicked on, at which point you'd be forwarded to the site, at which point NOD32 can prevent the site from loading anyway.
No, links are scanned the same way regardless if they point to an image, website, executable, etc. (in the end, it's not possible to figure this out until the target file is downloaded). If there's a blocked url within another url, the whole url will be blocked. If you want to access that site anyways, you can add beinsure.co.cc to the list of addresses excluded from content filtering (not sure if there's no malicious file hosted on the domain though).
  #12  
Old March 19th, 2012, 10:01 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Blocked internet jpg files

Quote:
Originally Posted by Marcos
No, links are scanned the same way regardless if they point to an image, website, executable, etc. (in the end, it's not possible to figure this out until the target file is downloaded). If there's a blocked url within another url, the whole url will be blocked. If you want to access that site anyways, you can add beinsure.co.cc to the list of addresses excluded from content filtering (not sure if there's no malicious file hosted on the domain though).

If I understand you correctly you're saying this feature is in place in the case that a "good" domain forwards to a malicious link. But when this happens a second request needs to be made to the malicious domain anyway to download the file, at which point NOD32 can block that second request. Am I wrong?

I *think* the real reason for this feature is to protect against malicious files through a proxy site? But Bing images isn't a proxy and as so should be added to a whitelist. I've encountered similar issues with other services such as Norton safe web, and the solution is always to add the originating domain (that isn't a proxy) to a whitelist.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #13  
Old March 19th, 2012, 12:29 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: Blocked internet jpg files

From my understanding and if I am explaining it correctly, these thumbnails are kind of like an iFrame. The page is hosted by Bing but the contents of the thumbnail boxes come from the sites they are hosted on. If one of those sites has any malicious files, the entire domain is blocked by ESS, therefore it cannot be contacted to link to the graphic. I don't believe Bing is being blocked in any way, it is the 3rd party site, which causes the graphic to not show. Hopefully that is somewhat correct and I am not just adding to the confusion.
  #14  
Old March 19th, 2012, 01:26 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Blocked internet jpg files

Quote:
Originally Posted by xxJackxx
The page is hosted by Bing but the contents of the thumbnail boxes come from the sites they are hosted on.

I just double-checked, all thumbnails are hosted by Bing, they are simply named after their location which gives the illusion that it is originating from a different site.

Click image for larger version

Name:	bing.png
Views:	8
Size:	30.0 KB
ID:	232186
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #15  
Old March 19th, 2012, 04:55 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: Blocked internet jpg files

Quote:
Originally Posted by funkydude
I just double-checked, all thumbnails are hosted by Bing, they are simply named after their location which gives the illusion that it is originating from a different site.

I would have been tempted to disagree but I did a test. I opened up a virtual machine with no AV installed and went to yesterday's Bing page. All thumbnails showing. I edited the HOSTS file and blocked beinsure.co.cc and tested again (I flushed the DNS cache to make sure). The thumbnail still shows, but clicking on it brings up a "page not found" so it looks like you are right.
  #16  
Old March 19th, 2012, 06:22 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Blocked internet jpg files

Well at least you confirmed it. It's up to ESET to add ts1-4.mm.bing.net to the whitelist. Though I still think it's silly not to restrict the check to the originating domain on the off chance that someone will use a proxy that displays the domain name in the address field (usually obfuscated).
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:25 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums