{"id":5738,"date":"2023-03-03T20:24:49","date_gmt":"2023-03-04T01:24:49","guid":{"rendered":"https:\/\/www.exchangedefender.com\/blog\/?p=5738"},"modified":"2023-03-03T20:27:03","modified_gmt":"2023-03-04T01:27:03","slug":"exchangedefender-phishing-firewall-is-live","status":"publish","type":"post","link":"https:\/\/www.exchangedefender.com\/blog\/2023\/03\/exchangedefender-phishing-firewall-is-live\/","title":{"rendered":"ExchangeDefender Phishing Firewall is Live!"},"content":{"rendered":"\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a href=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/03\/Admin-Portal-announcement-22-23-3.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/03\/Admin-Portal-announcement-22-23-3.jpg\" alt=\"\" class=\"wp-image-5743\" width=\"727\" height=\"609\" srcset=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/03\/Admin-Portal-announcement-22-23-3.jpg 940w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/03\/Admin-Portal-announcement-22-23-3-300x251.jpg 300w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/03\/Admin-Portal-announcement-22-23-3-768x644.jpg 768w\" sizes=\"auto, (max-width: 727px) 100vw, 727px\" \/><\/a><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong><a href=\"https:\/\/www.exchangedefender.com\/blog\/2023\/02\/exchangedefender-phishing-firewall-update\/\">As mentioned previously<\/a><\/strong> our new ExchangeDefender Phishing Firewall went live in production at noon EST today (March 3rd, 2023) and is already rewriting URLs unique to service provider that manages the domain.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">A little bit about the technology<\/h3>\n\n\n\n<p><br>URL \/ link rewriting is an industry standard used by biggest email providers to rewrite potentially dangerous URLs. When the user clicks on the link they are redirected to a Phishing Firewall site instead of the direct web site address that was in the email. The phishing firewall looks at all the domain policies, allow\/block lists, exceptions, and determines if the user should be allowed to proceed to the web site.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-black-color has-white-background-color has-text-color has-background\">When the messages arrive into your organization, instead of&nbsp;<strong>https:\/\/www.yahoo.com<\/strong>&nbsp;the URL is rewritten to something like&nbsp;<strong>https:\/\/<mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">exchangedefender<\/mark><\/strong>.<strong>xdref.com\/url=hash<\/strong>. These masked URLs are only visible to our clients, when they reply to an email the outbound network reverses the process. Outbound network replaces&nbsp;<strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-black-color\">https:\/\/<\/mark><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">exchangedefender<\/mark><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-black-color\">.xdref.com\/url=hash<\/mark><\/strong>with the original URL.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>This technology eliminates the possibility that a random hacker can deliver a payload that is one click away from the user. Additionally, it gives the user the ability to check the site reputation, check for viruses, and clearly see the URL they are going (instead of a squashed little tooltip with a 200+ character URL). Essentially, we study how people get hacked with phishing and try to eliminate those issues.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>All the sites and services are fully encrypted and partners\/clients do not need to worry about certificate renewals, site mappings, etc &#8211; everything is automatic and done for you. Set it and&nbsp;<s>forget it<\/s>&nbsp;just keep an eye on the logs.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Going Forward<\/h2>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>As of March 3rd, 2023 all the URLs will be rewritten using service providers id. Main benefit of this upgrade is that it reduces the scope and likelihood that the URL gets inadvertently reported or picked up by another security service that may deem&nbsp;<a target=\"_blank\" href=\"http:\/\/xdref.com\/\" rel=\"noreferrer noopener\">xdref.com<\/a>&nbsp;to be a masking site for dangerous content.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Additionally, you can configure your firewall to only accept unapproved URLs after a hop through &lt;<strong>yourspid<\/strong>&gt;.<a rel=\"noreferrer noopener\" href=\"http:\/\/xdref.com\/\" target=\"_blank\">xdref.com<\/a>. It also gives you full visibility into everything that happens with the URL, who clicks on it, where they go, etc which is something we do for our clients to address cybersecurity compromise and trace back how it happened (very lucrative service for partners that may be interested in deploying that level of protection.<\/p>\n","protected":false},"excerpt":{"rendered":"<p> [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[153,88],"class_list":["post-5738","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-exchangedefender-phishing-firewall","tag-phishing"],"_links":{"self":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts\/5738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/comments?post=5738"}],"version-history":[{"count":8,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts\/5738\/revisions"}],"predecessor-version":[{"id":5747,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts\/5738\/revisions\/5747"}],"wp:attachment":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/media?parent=5738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/categories?post=5738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/tags?post=5738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}