Hello All,
I need to pick the big brains here at TT. We are a medium size B2B business that onboards new clients daily. We have requirements that they have a functioning website, with a working cart, and have similar inventory to what we provide. This requires one of our employees to visit whatever website they put in the form to verify those criteria. Obviously, one bad actor figuring out our practice can take advantage of that easily. I am shopping ideas to mediate this exposure.
Currently, we are using and virustotal to get an idea if the site is legit or has been flagged in the past. The problem with that approach is it is more reactive in nature. Most of the DNS records I see used in email attacks are created that day, meaning virus total likely wont have had enough data to flag appropriately. And URL scan doesnt give a sandbox approach allowing you to click and see other links. You only can see the front page.
I thought about spinning up a VM in the DMZ and allowing one way RDP traffic to it from our LAN and allowing them to view sites off our internal network. That seems like a lot to remedy this. Does anyone know of a software or website that you can utilize, free or paid, that will allow you to enter a URL and traverse the site in a sandbox-esque environment?
Learning - A never ending quest for knowledge usually attained by being thrown in a situation and told to fix it NOW.
I need to pick the big brains here at TT. We are a medium size B2B business that onboards new clients daily. We have requirements that they have a functioning website, with a working cart, and have similar inventory to what we provide. This requires one of our employees to visit whatever website they put in the form to verify those criteria. Obviously, one bad actor figuring out our practice can take advantage of that easily. I am shopping ideas to mediate this exposure.
Currently, we are using and virustotal to get an idea if the site is legit or has been flagged in the past. The problem with that approach is it is more reactive in nature. Most of the DNS records I see used in email attacks are created that day, meaning virus total likely wont have had enough data to flag appropriately. And URL scan doesnt give a sandbox approach allowing you to click and see other links. You only can see the front page.
I thought about spinning up a VM in the DMZ and allowing one way RDP traffic to it from our LAN and allowing them to view sites off our internal network. That seems like a lot to remedy this. Does anyone know of a software or website that you can utilize, free or paid, that will allow you to enter a URL and traverse the site in a sandbox-esque environment?
Learning - A never ending quest for knowledge usually attained by being thrown in a situation and told to fix it NOW.