<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google Docs Phishing Issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32044#M23480</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I fully understand the need for training users and we do that but there are those who will never learn/listen. URL Filtering is a critical piece of our security arsenal. We pay money to have a company (PaloAlto and Brightcloud) find and categorize websites. I understand it cannot be 100% accurate or up to date.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Google Docs is a safe haven for Phishers is it not ? They hide behind a legit certificate which PA cannot filter on because it is not the same as the URL. If I was Google I would be concerned and I'm sure they are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can create a decryption rule but do not want to turn this on for everywhere. I'd have to think that any list of google subnets would be only temporarily accurate at best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a pickle.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 May 2012 17:41:31 GMT</pubDate>
    <dc:creator>jickfoo</dc:creator>
    <dc:date>2012-05-08T17:41:31Z</dc:date>
    <item>
      <title>Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32042#M23478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I dont know if its just us but we are getting hammered with phishing requests to google docs web sites. The latest is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.google.com/a/smps.k12.ok.us/spreadsheet/viewform?formkey=dGdKTFpTcW5KVVF1UGxJTFJ0aF9UdHc6MQ"&gt;https://docs.google.com/a/smps.k12.ok.us/spreadsheet/viewform?formkey=dGdKTFpTcW5KVVF1UGxJTFJ0aF9UdHc6MQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My URL Filter wont block this because it is SSL. It can read the cert which points to *.google.com but not the specific URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I'm not opposed to turning on SSL decryption but I dont want to turn it on for everything. Also, I dont understand how I can create the rule using IP Addresses as I'm sure docs.google.com has hundreds of IP Addresses associated with it. I also cant import a cert to everyones machine. Thats just not practicle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm angry that google would let this go on but its becoming a real issue for us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any creative ideas out there on how to block this type of SSL phishing attempt ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 12:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32042#M23478</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2012-05-08T12:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32043#M23479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patch your users &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well there are billions of phishing URLs around the world. Defeating phishing is usually a problem of education. The form you pasted here can be duplicated/reacreated with a new URL/ID everyday, so it would never end in URL blacklist.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 16:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32043#M23479</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-08T16:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32044#M23480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I fully understand the need for training users and we do that but there are those who will never learn/listen. URL Filtering is a critical piece of our security arsenal. We pay money to have a company (PaloAlto and Brightcloud) find and categorize websites. I understand it cannot be 100% accurate or up to date.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Google Docs is a safe haven for Phishers is it not ? They hide behind a legit certificate which PA cannot filter on because it is not the same as the URL. If I was Google I would be concerned and I'm sure they are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can create a decryption rule but do not want to turn this on for everywhere. I'd have to think that any list of google subnets would be only temporarily accurate at best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a pickle.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 17:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32044#M23480</guid>
      <dc:creator>jickfoo</dc:creator>
      <dc:date>2012-05-08T17:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32045#M23481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The future problem of security. Everyone hiding behind SSL. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say you could either use SSL Decryption, block Google Docs, or get fancy and use the Block and Continue function of the URL filtering to include a nice message about phishing scams.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 20:39:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32045#M23481</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2012-05-08T20:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32046#M23482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyway, anyone can create a new google account everyday, and create a doc with a form like you showed in a few seconds. Does it mean that Brightcloud should ban the X millions clones of same phishing form ? Pointless and performance hungry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 20:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32046#M23482</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-08T20:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32047#M23483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If URL filtering is such critical piece of your security arsenal then you REALLY should enable ssl decryption (for all outbound ssl connections).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way the URL filter can do a better job and you will also be able to perform IDP, file, AV and other filtering on the flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can in the decryption policy for example exclude banking if you have some privacy concerns in your organisation and at the same time make sure that ssl flows that cannot be decrypted will be blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also dont forget to change that "url-filtering &amp;lt;name&amp;gt; license-expired" so it will "block" if your URL filtering license expires (otherwise ALL sites will suddently be available).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 20:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32047#M23483</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-08T20:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Google Docs Phishing Issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32048#M23484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;essnet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they then advertise this website to millions of users then yes, brightcould should find reports of this instance and block it. They are already doing it. I look up the links in their database and more often then not they are correctly identified as 'Phishing and Other Scams'. I dont get the argument against URL filtering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll kick the tires with SSL Decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 21:10:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/google-docs-phishing-issues/m-p/32048#M23484</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2012-05-08T21:10:25Z</dc:date>
    </item>
  </channel>
</rss>

