{"id":3040,"date":"2016-11-08T10:00:35","date_gmt":"2016-11-08T17:00:35","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=3040"},"modified":"2016-11-08T10:00:35","modified_gmt":"2016-11-08T17:00:35","slug":"more-evidence-that-sitelocks-trueshield-web-application-firewall-is-really-incapsulas-waf","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/08\/more-evidence-that-sitelocks-trueshield-web-application-firewall-is-really-incapsulas-waf\/","title":{"rendered":"More Evidence That SiteLock&#8217;s TrueShield Web Application Firewall Is Really Incapsula&#8217;s WAF"},"content":{"rendered":"<p>Last week we looked at the evidence we had found that a couple of services that <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/11\/02\/is-sitelock-lying-about-patent-pending-technology-and-the-true-source-of-some-of-their-services\/\">SiteLock was claiming to provide directly were actually provided by Incapsula<\/a>. That would be an issue both because you have a security company pretty blatantly lying, but also because websites using the services would have traffic is going through a company they are neither aware would have access to their traffic and or that they have a relationship with.<\/p>\n<p>For one of the services, Sitelock&#8217;s\u00a0TrueSpeed\u00a0CDN, the evidence was beyond a reasonable doubt to us that the service is really provided by Incapsula. For their\u00a0TrueShield Web Application Firewall (WAF) it seemed likely that was also the case, due in part that it would be easier to use Incapsula&#8217;s WAF when they already were using their CDN, but the evidence wasn&#8217;t as strong. We ran into another piece of evidence that makes it pretty conclusive that the service is also actually provided by Incapsula.<\/p>\n<p>While requesting a page be saved on archive.org, so that we could link to it if it got removed from the website it was on, this was saved instead:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-captcha-page.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3044 size-full\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-captcha-page.png\" alt=\"sitelock-trueshield-web-application-firewall-captcha-page\" width=\"910\" height=\"630\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-captcha-page.png 910w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-captcha-page-300x208.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-captcha-page-768x532.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<p>That page claims that the website is &#8220;protected and accelerated by SiteLock&#8221; and that there is a &#8221; SiteLock security network&#8221;:<\/p>\n<blockquote><p><span style=\"font-style: italic;\">The web site you are visiting is protected and accelerated by <\/span><a style=\"font-style: italic;\" href=\"https:\/\/web.archive.org\/web\/20161107234131\/http:\/\/www.sitelock.com\/\" target=\"_blank\">SiteLock<\/a><span style=\"font-style: italic;\">. Your computer might have been infected by some kind of malware and flagged by <\/span><a style=\"font-style: italic;\" href=\"https:\/\/web.archive.org\/web\/20161107234131\/http:\/\/www.sitelock.com\/\" target=\"_blank\">SiteLock<\/a><span style=\"font-style: italic;\"> security network. This page is presented by SiteLock to verify that a human is behind the traffic to this site and malicious software.<\/span><\/p><\/blockquote>\n<p>Here is one of a number a screenshots we found with of the exact same page when coming from Incapsula:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/incapsula-waf-captcha-page.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3047\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/incapsula-waf-captcha-page.png\" alt=\"incapsula-waf-captcha-page\" width=\"910\" height=\"600\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/incapsula-waf-captcha-page.png 910w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/incapsula-waf-captcha-page-300x198.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/incapsula-waf-captcha-page-768x506.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<p>The only difference with it\u00a0is the branding. There really isn&#8217;t a way that could be coincidental.<\/p>\n<p>That doesn&#8217;t match with SiteLock&#8217;s <a href=\"https:\/\/www.sitelock.com\/web-application-firewall\">description on the page\u00a0for the service though<\/a>. For example, they claim that SiteLock is analyzing the request, when in fact it is Incapsula:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-diagram.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3048\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-diagram.png\" alt=\"sitelock-trueshield-web-application-firewall-diagram\" width=\"920\" height=\"670\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-diagram.png 920w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-diagram-300x218.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-trueshield-web-application-firewall-diagram-768x559.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week we looked at the evidence we had found that a couple of services that SiteLock was claiming to provide directly were actually provided by Incapsula. That would be an issue both because you have a security company pretty blatantly lying, but also because websites using the services would have traffic is going through &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/08\/more-evidence-that-sitelocks-trueshield-web-application-firewall-is-really-incapsulas-waf\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;More Evidence That SiteLock&#8217;s TrueShield Web Application Firewall Is Really Incapsula&#8217;s WAF&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[39,99],"class_list":["post-3040","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-sitelock","tag-trueshield-web-application-firewall"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3040"}],"version-history":[{"count":5,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3040\/revisions"}],"predecessor-version":[{"id":3049,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3040\/revisions\/3049"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}