Urlscan.io’s SOAR spot: Chatty security tools leaking private data
positive.security
Urlscan.io’s SOAR spot: Chatty security tools leaking private data
1–8 of 8 posts
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#2There are some times where cloud based solutions aren't the best option, and it seems like this may be one of them
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#3Sounds similar to Virustotal, where customers can get access to uploaded files, so if you use it to scan documents for malware, you might end up leaking them. There are some times where cloud based solutions aren't the best option, and it seems like this may be one of them
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#4Sounds similar to Virustotal, where customers can get access to uploaded files, so if you use it to scan documents for malware, you might end up leaking them. There are some times where cloud based solutions aren't the best option, and it seems like this may be one of them
URLScan has a private submission mode.
"However, when continuously monitoring the above result page, sometimes some fresh additional entries can be spotted, which disappear again within around 10 minutes.
We later found out that Apple has in the meantime requested an exclusion of their domains from the scan results, which is implemented via periodically deleting all scan results matching certain rules."
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#5But wow! I did not realize just how much data they had access to and the types of URLs people would want scanned.
That being said, good on urlscan for making changes, reaching out to customers and setting up a best practice guide in response to these concerns.
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#6Any feature requests or things you'd like to see that Cloudflare could do differently?
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#7Why would the default behavior be to share URLs with all parameters publicly? Am I missing or misunderstanding something here, because this sounds insane? The security model of basically every online service depends on the absolute secrecy of full URLs in emails, right? Email is treated like root.
Re: Urlscan.io’s SOAR spot: Chatty security tools leaking private data
#8We're (Cloudflare) working on expanding our URL scanning tool, currently located within the Security Center "Investigate" tab. Any feature requests or things you'd like to see that Cloudflare could do differently?
The use case for this was take down requests of lookalike / copycat domains. Some of these, we found, were being used (or attempted to be used) in more advanced phishing campaigns.