Skip to main content
Question

Sophos blocks Custom Transformers from the Hub


cory
Contributor
Forum|alt.badge.img+7

Hi team,

I've seen this at multiple locations, where Sophos will prevent FME from installing custom transformers from the Hub (i.e. Emailer) and display a Lockdown alert, Sophos believes it to be malicious behavior.

 

Has anyone else experienced this? Is it possible for Safe to reach out to Sophos to see if this can be looked at, as the only way to get around this, is to allow exceptions per Transformer on the Sophos side and we have to re-do this each time we upgrade FME Desktop.

7 replies

hkingsbury
Celebrity
Forum|alt.badge.img+51
  • Celebrity
  • August 28, 2022

Is this downloading the file through the browser or fetching it using Workbench?


cory
Contributor
Forum|alt.badge.img+7
  • Author
  • Contributor
  • August 30, 2022
hkingsbury wrote:

Is this downloading the file through the browser or fetching it using Workbench?

It's downloading it via Workbench and installing it automatically (well trying to)


hkingsbury
Celebrity
Forum|alt.badge.img+51
  • Celebrity
  • August 30, 2022
cory wrote:

It's downloading it via Workbench and installing it automatically (well trying to)

Try downloading it through your browser and installing it manually

https://hub.safe.com/publishers/safe/packages/emailer


  • August 30, 2022

I've experienced this exact issue - it would be nice if we could install custom transformers from Hub without Sophos blocking them.


siennaatsafe
Safer
Forum|alt.badge.img+10
ashh wrote:

I've experienced this exact issue - it would be nice if we could install custom transformers from Hub without Sophos blocking them.

Hi @ashh​ ,

 

Sorry, you are experiencing this! I've filed a ticket on our end to see if there is anything we can do to prevent this.

 

I spoke to a developer about this and he said the reason this may be happening is that we are essentially downloading .zip files that contain Python which may raise a red flag.

 

Just to confirm, if you go to FME Hub and download the files directly, does that work?

 

The developers were also interested in seeing any error logs from Sophos you may have. They did warn me, that there may be nothing they can do, as Sophos is third-party software and there may be settings that we cannot work around. However, we'd like to take a look to see if there is something we could be handling better!


cory
Contributor
Forum|alt.badge.img+7
  • Author
  • Contributor
  • May 31, 2023
siennaatsafe wrote:

Hi @ashh​ ,

 

Sorry, you are experiencing this! I've filed a ticket on our end to see if there is anything we can do to prevent this.

 

I spoke to a developer about this and he said the reason this may be happening is that we are essentially downloading .zip files that contain Python which may raise a red flag.

 

Just to confirm, if you go to FME Hub and download the files directly, does that work?

 

The developers were also interested in seeing any error logs from Sophos you may have. They did warn me, that there may be nothing they can do, as Sophos is third-party software and there may be settings that we cannot work around. However, we'd like to take a look to see if there is something we could be handling better!

Hi @siennaatsafe​  -- Yes this is correct. Even downloading this via the web, Sophos still blocks it.

 

From what we can see, it looks like it's executing multiple processes which is what raises the red flag with Sophos.


siennaatsafe
Safer
Forum|alt.badge.img+10

@cory​ ,

Some of our developers took a look at the Sophos documentation and it looks like there is a way to stop detecting these false positives. 

Would it be possible for you to try the steps in this link to see if that alleviates the issue?


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings