<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to block method POST in any website? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33321#M24405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case would it be best to create a custom app or a custom signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I (currently) think that creating a custom signature would be better that acts on all http traffic and by that set an default action of block (or alert).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Jul 2013 18:15:24 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-07-04T18:15:24Z</dc:date>
    <item>
      <title>Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33316#M24400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Our company don't want employee to post anything on internet so we're trying to create custom application that block method POST on http-request-message. But when we're trying to write a pattern. It's always pop up an alert to say that at least 7 bytes require. we've tried it so many ways such as [a-zA-Z0-9] but it still won't working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Can anybody advice us to write a pattern that will be match any message? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Piyapol&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 04:40:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33316#M24400</guid>
      <dc:creator>pjetiyanun</dc:creator>
      <dc:date>2013-07-04T04:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33317#M24401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Helpful References&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For help with understanding strings or inputs that match a RegEx pattern, try &lt;A class="jive-link-external-small" href="http://regexpal.com/" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;Regex Tester&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;For help with understanding RegEx, check: &lt;A class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Regular_expression" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;Regular expression - Wikipedia, the free encyclopedia&lt;/A&gt; or &lt;A class="jive-link-external-small" href="http://www.regular-expressions.info/" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;Regular-Expressions.info - Regex Tutorial, Examples and Reference - Regexp Patterns&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;For how the PAN RegEx engine works, refer to &lt;A _jive_internal="true" data-containerid="2010" data-containertype="14" data-objectid="1499" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1499" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;Regular expression syntax for patterns in custom app signatures&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;TechNote : &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2015"&gt;Custom Application Signatures&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 04:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33317#M24401</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-04T04:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33318#M24402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Similar discussion can be found here &lt;/SPAN&gt;&lt;A class="" href="https://live.paloaltonetworks.com/message/14234#14234"&gt;https://live.paloaltonetworks.com/message/14234#14234&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 05:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33318#M24402</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-07-04T05:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33319#M24403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also refer page 156 of &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2029"&gt;https://live.paloaltonetworks.com/docs/DOC-2029&lt;/A&gt; under the heading Example - Detect a post to a specified blog&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 05:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33319#M24403</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-07-04T05:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33320#M24404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically for a Custom-Signature based on the HTTP-POST request ,you can add Context&lt;STRONG&gt; http-req&lt;/STRONG&gt;&lt;STRONG&gt;-uri-path&lt;/STRONG&gt; and then add a qualifier as &lt;STRONG&gt;http-method &lt;/STRONG&gt;with&lt;STRONG&gt; Value=Post&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="7184" alt="Capture.PNG" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7184_Capture.PNG" style="width: 450px; height: 414px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 05:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33320#M24404</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-04T05:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33321#M24405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case would it be best to create a custom app or a custom signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I (currently) think that creating a custom signature would be better that acts on all http traffic and by that set an default action of block (or alert).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 18:15:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33321#M24405</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-04T18:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33322#M24406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thankyou for all answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I can't block path /imgs , /files because palo alto alert " &lt;STRONG&gt;The minimum length for this field is 7&lt;/STRONG&gt; ".&lt;/P&gt;&lt;P&gt;I test insert /imgs{7}.&amp;nbsp; It not work.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Refer : &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;{ } Min/Max number of bytes. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Example: {10,20} matches any string that is between 10 and 20 bytes. This must be directly in &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;front of fixed string, and only supports “.”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share any idea to fix It.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 02:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33322#M24406</guid>
      <dc:creator>pjetiyanun</dc:creator>
      <dc:date>2013-07-05T02:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33323#M24407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We found the same problem here. I've try create an pattern like [a-zA-Z0-9] which should match everything already (tested on &lt;A href="http://regexpal.com/" title="http://regexpal.com/"&gt;Regex Tester&lt;/A&gt;). And also use &lt;A href="http://bytecount.bluebus112.com/" title="http://bytecount.bluebus112.com/"&gt; Byte Counter &lt;/A&gt; to count this pattern which it said 11 bytes. But On Paloalto, when we tried to add. Same errors pop up like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ebedee;"&gt;-&amp;gt; signature -&amp;gt; PostMethod -&amp;gt; and-condition -&amp;gt; And Condition 1 -&amp;gt; or-condition -&amp;gt; Or Condition 1 -&amp;gt; operator -&amp;gt; pattern-match -&amp;gt; pattern '[a-zA-Z0-9]' is invalid. pattern must be at least 7 byte&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 04:42:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33323#M24407</guid>
      <dc:creator>Mark-Nakrop</dc:creator>
      <dc:date>2013-07-05T04:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block method POST in any website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33324#M24408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Context: http-req-header&lt;/P&gt;&lt;P&gt;Qualifier: http-method&lt;/P&gt;&lt;P&gt;Value: POST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and yet it complains that there is no pattern... hmpf... so damn close &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there some kind of bogus wildcard one can use to make the GUI happy, like ******* (seven * in a row) or such?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is this example in the manual which is sort of what is needed, except that this signature (which this thread is needing) should trigger on ANY site (no matter if its ipv4, ipv6 or fqdn) and that this example is an appid instead of a vuln signature which would be a better choice:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set application specifiedblog_posting category collaboration subcategory web-posting technology browser-based signature s1 and-condition a1 or-condition o1 operator pattern-match context http-req-host-header pattern specifiedblog.com qualifier http-method value POST&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 08:17:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-block-method-post-in-any-website/m-p/33324#M24408</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-05T08:17:49Z</dc:date>
    </item>
  </channel>
</rss>

