<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire &amp; ZIP files in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41882#M30810</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just so I am clear...&amp;nbsp; The only file type I have enabled right now is PE.&amp;nbsp; Do I need to enable ZIP or is this handled automatically (and then PE types in the zip are scanned).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Nov 2013 21:26:06 GMT</pubDate>
    <dc:creator>nthen</dc:creator>
    <dc:date>2013-11-22T21:26:06Z</dc:date>
    <item>
      <title>Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41880#M30808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I have the PE type selected for Wildfire are ZIP files sent to be scanned if they contain EXE files?&amp;nbsp; I thought they were, but figured I would ask.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 20:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41880#M30808</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-11-22T20:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41881#M30809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/20426"&gt;nthen&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Yes you are right. Exe files contained in zip files can be forwarded to Wildfire and scanned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Proof (shows &lt;SPAN style="font-family: 'Helvetica Neue',Helvetica,Arial,'Lucida Grande',sans-serif; font-size: 13px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;pck2302.zip containing 25 exe files&lt;/SPAN&gt; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5658"&gt;https://live.paloaltonetworks.com/docs/DOC-5658&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;As far as PE file types are concerned, currently we support the following extensions -- &lt;/SPAN&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;exe, dll, com, scr, ocx, cpl, sys, drv, tlb&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;Hope that is the information you were looking for.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;Kunal Adak&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 21:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41881#M30809</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-22T21:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41882#M30810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just so I am clear...&amp;nbsp; The only file type I have enabled right now is PE.&amp;nbsp; Do I need to enable ZIP or is this handled automatically (and then PE types in the zip are scanned).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 21:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41882#M30810</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-11-22T21:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41883#M30811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello nthen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kadak has shared some good knowledge. To add a point, In identifying the PE files with in ZIP files we go 3 iterations down in zip files to see if there is a PE file. So in general they should be extracted and caught by the cloud for PE malware analysis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 21:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41883#M30811</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-11-22T21:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41884#M30812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will have to add ZIP file types in the file blocking profile to monitor for PE files with in Zip files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 21:28:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41884#M30812</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-11-22T21:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41885#M30813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As long as the session transferring the ZIP has Layer 7 processing enabled, the zip will get decompressed and the PE file will match the File Blocking profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is NOT required to configure File Blocking profile to include ZIP file type.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Nov 2013 19:30:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/41885#M30813</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-11-23T19:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/151924#M50266</link>
      <description>&lt;P&gt;Got a WF/Zip question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How does a FW with WF handle multiple levels of zip encoding? &amp;nbsp;Is there an upper limit of "levels" a file has been zipped?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a related note any reason why the WF Portal can't accept a zip file?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 14:57:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/151924#M50266</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-10T14:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/151946#M50274</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lookee here: &lt;A title="Tips &amp;amp; Tricks: Multi-Level Encoding and Blocking (File Blocking Profile)" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Multi-Level-Encoding-and-Blocking-File-Blocking/ta-p/90414" target="_blank"&gt;Tips &amp;amp; Tricks: Multi-Level Encoding and Blocking (File Blocking Profile)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There may be several reasons zip files are not accepted, possibly to prevent needing to unpack many non-scannable files&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 15:40:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/151946#M50274</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-10T15:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/151947#M50275</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;So if I'm understanding correctly a file which has been "zipped" 3 times with the actual file being a .exe could be analyzed&amp;nbsp;for "maliciousness." &amp;nbsp;If there was a 4th level of zip encoding of maybe some other .docx attached to a .pptx would be beyond the &amp;nbsp;4 layers of encoding and as such would only be seen as "multi-level encoding" from a WF perspective on the firewall?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 15:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/151947#M50275</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-04-10T15:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire &amp; ZIP files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/152137#M50334</link>
      <description>&lt;P&gt;yes, a PE file could be in 4 zips deep if sent over a plain connection, but a docx only 3 because the docx itself is encoded, the transport layer itself also counts so if it's sent over http chunk encoding you could only go 3 deep for the PE or 2 for the docx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once the number of levels is exceeded, the file blocking profile (and per extention WildFire) would only see multi-level-encoding and act upon your policy to allow or deny, but no longer forward&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 07:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-zip-files/m-p/152137#M50334</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-11T07:16:13Z</dc:date>
    </item>
  </channel>
</rss>

