-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bug: "ip-block-list - snort.org" feed failing with 403 errors #9707
Comments
Yep, observed the same with snort and a couple of other txt feeds, in Ubuntu based MISP. The URL actually redirects to something like https://snort-org-site.s3.amazonaws.com/production/document_files/files/000/030/929/original/ip-filter.blf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAU7AK5ITMMOXGB2W5%2F20240523%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20240523T091133Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=920528cee70eee181c1233170068a62a49fae18be6b6c36a7f3c33fa157d0c6c And this is probably the reason for seeing this |
I've tested it adding an additional header "User-Agent" with value "MISP" in __createFeedRequest and it resolves this issue. Can someone please write a patch? |
Actual behavior
We're getting 403 errors when we attempt to fetch attributes from the "ip-block-list - snort.org". We were successfully pulling this feed, but seemingly out of nowhere this started happening. Interestingly if we do a
wget https://snort.org/downloads/ip-block-list
on the server, it can pull the file with no issues.See full error message below.
Expected behavior
We expect to be able to retrieve attributes from the feed without errors.
Steps to reproduce
Fetch attributes from the "ip-block-list - snort.org" default feed. This fails with triggering in the web application and via the CLI.
Version
2.4.190
Operating System
RedHat
Operating System version
7.9
PHP version
7.4.33
Browser
No response
Browser version
No response
Relevant log output
Extra attachments
No response
Code of Conduct
The text was updated successfully, but these errors were encountered: