<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: block files with multiple level of compression in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20352#M14834</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, I just did a test by FTPing a malicious .exe file that was compressed inside of a .ZIP. My Data Filtering log shows the action for the .PE file within the .ZIP as "forward" however, I did not receive anything from the Wildfire Cloud. Also, the Wildfire Portal has no entry for this file being uploaded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insight as to why Wildfire did not receive the file that had the "forward" action?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 May 2013 12:40:31 GMT</pubDate>
    <dc:creator>jwolach</dc:creator>
    <dc:date>2013-05-14T12:40:31Z</dc:date>
    <item>
      <title>block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20345#M14827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to block all kind of compressed files with more than the support 2 levels of compressions. Is this possible?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 09:46:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20345#M14827</guid>
      <dc:creator>azwicker</dc:creator>
      <dc:date>2013-03-21T09:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20346#M14828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean like an arj within a rar within a zip?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 21:47:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20346#M14828</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-22T21:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20347#M14829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;PAN performs a maximum of 2 levels of decompression&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-7562"&gt;IPS Scanning of Compressed Files&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 23:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20347#M14829</guid>
      <dc:creator>knarra1</dc:creator>
      <dc:date>2013-03-22T23:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20348#M14830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know that the pa supports only 2 levels. My question was: Can i block files with more than 2 levels? In a test scenario, a exe file within a multiple zip file was not sent to wildfire.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 13:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20348#M14830</guid>
      <dc:creator>azwicker</dc:creator>
      <dc:date>2013-03-27T13:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20349#M14831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manually unpacking the file und uploading the exe to wildfire revealed a 0day infected file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 13:26:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20349#M14831</guid>
      <dc:creator>azwicker</dc:creator>
      <dc:date>2013-03-27T13:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20350#M14832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Be uploaded to wildfire only PE files. if more than 2 level of compression, file is seen as zip then no PE then no wildfire &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In my mind not able to block file with more than two level of compression.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 13:32:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20350#M14832</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-03-27T13:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20351#M14833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot block files with more than 2 levels of compression today.&amp;nbsp; If you would like this functionality, please contact your SE to submit a feature request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 19:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20351#M14833</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-03-27T19:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20352#M14834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, I just did a test by FTPing a malicious .exe file that was compressed inside of a .ZIP. My Data Filtering log shows the action for the .PE file within the .ZIP as "forward" however, I did not receive anything from the Wildfire Cloud. Also, the Wildfire Portal has no entry for this file being uploaded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insight as to why Wildfire did not receive the file that had the "forward" action?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 12:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20352#M14834</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2013-05-14T12:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20353#M14835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have seen the same issue... files that are apparently "forwarded" to WildFire never show up as malicious, even files that we know are malicious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have asked Palo Alto for a test .exe that we can send across the network and will always flag as malicious... another malware appliance we have does this exact thing (similar to the EICAR antivirus file you can test AV solutions with)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 12:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20353#M14835</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-05-14T12:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20354#M14836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I do to get malicious files to test with Wildfire, is go to malc0de.com, go to the Tools menu and then click on "Search Malc0de Database". Then I type in .exe in the search window. This will pull up a list of files that are either malicious or at benign but, will actually trigger Wildfire actions on the PANW. I download that files to my Macbook so, they will not infect my machine.&amp;nbsp; So far, so good for exercising Wildfire actions and the portal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 12:52:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20354#M14836</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2013-05-14T12:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20355#M14837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the tip! We actually had people from PA here yesterday and they weren't aware of your method&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 13:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20355#M14837</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-05-14T13:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: block files with multiple level of compression</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20356#M14838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't take full credit, I actually learned about malc0de.com from our local PAN SE. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; I hope it works out for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 13:47:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-files-with-multiple-level-of-compression/m-p/20356#M14838</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2013-05-14T13:47:16Z</dc:date>
    </item>
  </channel>
</rss>

