threat intelligence false positives?

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

threat intelligence false positives?

Unread post by faris »

A customer got shunned on one of my systems and it turned out that one of the Threat Intelligence rules 350054 had triggered.

Following the link I did a manual lookup and the IP was not listed, although it said "Reported by 1 Atomic Secured Linux users from 2 hosts."

Unfortunately I've never installed the necessary dnsbl stuff on this system, but "Atomicorp Threat Intelligence System" is ticked in the ASL config so I'm assuming it is doing lookups but not locally.

But given that the IP isn't in the RBL, why is it being blocked? I'm seeing a handful of other IPs that have been blocked by this rule, and some of them are definitely up to no good. But again, the ones I've checked always come up with "not in RBL" but are "reported by X users from Y hosts"

Incidentally, when trying to get to the wiki https://www.atomicorp.com/wiki/index.php/Atomicrbl linked from this page: https://atomicorp.com/atomicti/ I just get redirected to https://atomicorp.com/

Same with the forum link on that page.

I'm really, really confused :-)
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
Post Reply