<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking WORD docs which contain macros in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/75468#M41989</link>
    <description>&lt;P&gt;This is kind of an older question from 2011 but the whole macro thing especially regarding CryptoLocker spreading rapidly over the EMEA region is highly relevant. Any updates if such a macro blocking/dection (aka. finding active content in MIMEs) feature will be vailable in PAN-OS 8 - Such an extension to the AV/fileblocking database would be very nice. Plenty of e-mail gateways are doing this for the e-mail vector, also from a web vector perspective controlling files entering the company in a more granular would help a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...something like that for the http traffic side:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 519px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3276i7F921637E9CF8125/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2016 13:48:10 GMT</pubDate>
    <dc:creator>peter.schoenegger</dc:creator>
    <dc:date>2016-03-30T13:48:10Z</dc:date>
    <item>
      <title>Blocking WORD docs which contain macros</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/64507#M38653</link>
      <description>&lt;P&gt;In the course of a regular day, it is not uncommon to receive regular legit word documents from people via email. &amp;nbsp;However, increasingly we are getting documents pretending to be resumes, and the .doc file contains macros. &amp;nbsp;Our version of Word 2013 treats these as protected documents and the macros do not auto open like the malicious user intended. However, the content of the word document tries to trick our end user into clicking the "allow content" button. &amp;nbsp;Even if they do click, our firewall is blocking the attempted EXE download. &amp;nbsp;However, should the next round of word documents get more clever and change the download into something without an extension (possibly renaming during the download?) then I'd like to investigate the option of preventing Word documents with Macros from coming in through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that possible using a data filter?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Corbett.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 16:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/64507#M38653</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2015-09-11T16:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking WORD docs which contain macros</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/64550#M38674</link>
      <description>&lt;P&gt;According to PA executable files are not recognised only by extension but by file content so changing extension won't help the attacker. However i agree that blocking word docs with macros from internet could be a useful feature. I don't think there is such feature available yet. But&amp;nbsp;I guess a DLP filter which triggers on&amp;nbsp;typical macro functions and/or calls could work. Or some custom IPS signature maybe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 07:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/64550#M38674</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-09-14T07:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking WORD docs which contain macros</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/64584#M38692</link>
      <description>&lt;P&gt;The macros inside these malicious word docs are password protected, so I'd have to look for a string blocking all macros, of which I don't know how to do. &amp;nbsp;There is text inside each of these word docs that tries to make the user click the to disable extended security, so maybe I can scan for those words instead of looking for macros.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 15:08:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/64584#M38692</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2015-09-14T15:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking WORD docs which contain macros</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/75468#M41989</link>
      <description>&lt;P&gt;This is kind of an older question from 2011 but the whole macro thing especially regarding CryptoLocker spreading rapidly over the EMEA region is highly relevant. Any updates if such a macro blocking/dection (aka. finding active content in MIMEs) feature will be vailable in PAN-OS 8 - Such an extension to the AV/fileblocking database would be very nice. Plenty of e-mail gateways are doing this for the e-mail vector, also from a web vector perspective controlling files entering the company in a more granular would help a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...something like that for the http traffic side:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 519px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3276i7F921637E9CF8125/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 13:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-word-docs-which-contain-macros/m-p/75468#M41989</guid>
      <dc:creator>peter.schoenegger</dc:creator>
      <dc:date>2016-03-30T13:48:10Z</dc:date>
    </item>
  </channel>
</rss>

