<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Lock down Search Engines to Safe Searches in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49809#M36690</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great article and thanks for this. Is there any way to set google to strict search?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 May 2010 14:11:13 GMT</pubDate>
    <dc:creator>Billy_G</dc:creator>
    <dc:date>2010-05-14T14:11:13Z</dc:date>
    <item>
      <title>How to Lock down Search Engines to Safe Searches</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49808#M36689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are some custom vulnerabilities and one custom application I wrote to block unfiltered (Bad) searches on the big search engine sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These were written in 3.1.0 software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000; font-size: 14pt; text-decoration: underline; "&gt;&lt;STRONG&gt;UPDATE: See attached for 4.0 version of these vulnerabilities and custom application.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style=": ; color: #333333; text-decoration: underline; "&gt;Here is what they do:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Bing:&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Blocks all explicit content in images and videos&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Google:&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Users can’t change their search settings to Unfiltered or Moderate. They can change them to strict.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Google cached pages are blocked&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Blocks google completely for users who have set their search settings to unfiltered via another connection (like a laptop from home). If they clear there cookies they will go back to moderate and be fine again.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Block users who manually enter a google url that has safe search off in the URL string.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Yahoo&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Users can’t change their search settings to Safe Off.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Yahoo cached pages are blocked&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Altavista&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;SPAN style="font-family: Symbol;"&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Users can’t change their search settings to Safe Off.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;STRONG style="text-decoration: underline; "&gt;Here is how to implement these:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="color: #1f497d;"&gt;1.0&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d;"&gt;Vulnerabilities &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt;Just go to Objects, vulnerabilities, then import these threat definitions in one at a time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt;They have a default action on each of block so all you need to do is make sure that your web-browsing and any any&amp;nbsp; permit rules have vulnerability checking set to default under the profile section on each policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="color: #1f497d;"&gt;2.0&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d;"&gt;Custom U&lt;SPAN style="color: #1f497d;"&gt;nfiltered Google Applicati&lt;/SPAN&gt;on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt;Go to objects, applications, then click import. Import the&amp;nbsp; appid google-unfiltered.xml custom application definition.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt;Add a new policy trust to untrust any any any application=google-unfiltered deny application-default&amp;nbsp; (no profile needed)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt;Move this rule to the top, it will block any google traffic when the user has somehow set their search setting to completely unfiltered. They can’t do that through the Palo Alto so it would have to be a laptop from home or something.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;SPAN style="color: #1f497d;"&gt;3.0&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d;"&gt;Add Google cache to blocked URL list&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin-left: 0.25in;"&gt;&lt;SPAN style="color: #1f497d;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #1f497d;"&gt;The last step is to add &lt;/SPAN&gt;webcache.googleusercontent.com and *.explicit.bing.net to the black list in the URL filtering policy under objects and then use that URL filter policy on the Policy for the web-browsing traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;See attached files.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Good Luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 May 2010 15:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49808#M36689</guid>
      <dc:creator>u2913</dc:creator>
      <dc:date>2010-05-13T15:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to Lock down Search Engines to Safe Searches</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49809#M36690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great article and thanks for this. Is there any way to set google to strict search?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 14:11:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49809#M36690</guid>
      <dc:creator>Billy_G</dc:creator>
      <dc:date>2010-05-14T14:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to Lock down Search Engines to Safe Searches</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49810#M36691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem with forcing only strict google searches, is that the default google setting is moderate. So if you block moderate then you can block google completely and not be able to change your settings to strict from moderate even if you want to comply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yo create a new vulnerability signature with the following two lines then it will block everything but strict. Watch out in case you lock yourself out of google however.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pattern-match&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; http-req-headers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; google/.com&lt;/P&gt;&lt;P&gt;pattern-match&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; http-req-headers&amp;nbsp;&amp;nbsp; safeui=images&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or just download the attached signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 19:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49810#M36691</guid>
      <dc:creator>u2913</dc:creator>
      <dc:date>2011-08-22T19:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to Lock down Search Engines to Safe Searches</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49811#M36692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do this work when someone uses Yahoo as well? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 22:51:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-lock-down-search-engines-to-safe-searches/m-p/49811#M36692</guid>
      <dc:creator>cdamore</dc:creator>
      <dc:date>2013-01-17T22:51:43Z</dc:date>
    </item>
  </channel>
</rss>

